Intrusion detection using data mining – an overview of methods and their success

Marina Ilijanić, Danijela Jakšić, Patrizia Poščić · 2022 45th Jubilee International Convention on Information, Communication and Electronic Technology (MIPRO) · 2022

Problem of processing large volumes of data in a shorter amount of time is a regular occurrence nowadays. This is due to rapidly evolving technologies and Internet being used as the primary source for communication, viewing and searching information, performing transactions, etc. This results in frequent thefts of personal and professional data, as well as an increase of malware or SQL attacks. These are some of the most difficult problems for computers and networks to solve, as well as for information technology security specialists. Numerous tools and methods for detecting and suppressing malicious intrusions are no longer sufficient, so data mining is often being used for that purpose. This paper explains the types of intrusion detection systems and its techniques, the types of intrusions themselves, and briefly describes the most common datasets used in intrusion detection. The definition of data mining and the most common methods and algorithms of data mining are explained. An overview of related work in this field was given, as well as some conclusions based on this analysis. It was concluded that the Random Forest algorithm is the most successful in detecting intrusions, but that the best way to prevent intrusion is to create hybrid models.

Read the paper · More papers on PaperTik