A Study on Network Intrusion Detection System Based on Data Mining

Yimei Xu, Pengiu He, Panlong Sheng · 2023

Intrusion detection technology stands as a fundamental pillar in network security defense. With the ever-increasing bandwidth of network traffic, intrusion detection systems are required to offer rapid detection capabilities. The Snort intrusion detection system relies on matching captured data with predefined rules to determine if an attack has occurred. Therefore, the quality of rules directly impacts the system's performance. By integrating clustering algorithms and association rule algorithms from the field of data mining into traditional systems, automatic expansion and updating of rule libraries have been achieved. Clustering algorithms analyze the dataset through clustering analysis, retaining only the portions exhibiting anomalous behavior for system detection. Consequently, this approach reduces the time required for system detection analysis, thereby enhancing detection efficiency. The association rule algorithm establishes rule associations among the remaining anomalous data, and the generated rules are incorporated into the Snort rule library, effectuating automatic updates of the rule library. This maintains the real-time and effective nature of the detection system. Test results indicate that, with the optimization of clustering and association rule algorithms, the system's detection efficiency has been notably augmented, leading to approximately a 5% reduction in detection time compared to the traditional Snort system.

Read the paper · More papers on PaperTik