Logo image
A three-tier IDS via data mining approach
Conference paper   Open access

A three-tier IDS via data mining approach

Tsong Song Hwang, Tsung-Ju Lee and Yuh-Jye Lee
MineNet'07: Proceedings of the Third Annual ACM Workshop on Mining Network Data, pp.1-6
2007

Abstract

Activity profile Blacklist False alarm rate Intrusion detection system KDD'99 Multiclass SVMs RIPPER Whitelist Computer Science Applications Information Systems Theoretical Computer Science
We introduced a three-tier architecture of intrusion detection system which consists of a blacklist, a whitelist and a multi-class support vector machine classifier. The first tier is the blacklist that will filter out the known attacks from the traffic and the whitelist identifies the normal traffics. The rest traffics, the anomalies detected by the whitelist, were then be classified by a multi-class SVM classifier into four categories: PROBE, DoS, R2L and U2R. Many data mining and machine learning techniques were applied here. We design this three-tier IDS based on the KDD'99 benchmark dataset. Our system has 94.71% intrusion detection rate and 93.52% diagnosis rate. The averag cost for each connection is 0.1781. All of these results are better than those of KDD'99 winner's. Our three-tier architecture design also provides the flexibility for the practical usage. The network system administrator can add the new patterns into the blacklist and allows to do fine tuning of the whitelist according to the environment of their network system and security policy. Copyright 2007 ACM.
url
https://doi.org/10.1145/1269880.1269882View
Published (Version of record) Open

Related links

Metrics

1 Record Views

Details

Logo image