Data mining for intrusion detection

Liu Dihua, Wang Hongzhi, Wang Xiumei
2001 International Conferences on Info-Tech and Info-Net. Proceedings (Cat. No.01EX479)  
This paper presents an qproach to detect intrusion based on data mining framework. In the framework, intrusion detection is thought of as a classification. The central idea is to utilize auditing programs to extract an extensive set of features that describe each network connection or host session, and apply data mining programs to learn rules that accurately capture the behavior of intrusions and normal activities. These rules can then be used for misuse detection and anomaly detection. We
more » ... ide the results from the experiments in using classification on rea!-world traffic data.
doi:10.1109/icii.2001.983486 fatcat:v3rucntw2vahlnvemqlibztcsi