Scaling up Detection Rates and Reducing False Positives in Intrusion Detection using NBTree - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Scaling up Detection Rates and Reducing False Positives in Intrusion Detection using NBTree

Résumé

In this paper, we present a new learning algorithm for anomaly based network intrusion detection using improved self adaptive naïve Bayesian tree (NBTree), which induces a hybrid of decision tree and naïve Bayesian classifier. The proposed approach scales up the balance detections for different attack types and keeps the false positives at acceptable level in intrusion detection. In complex and dynamic large intrusion detection dataset, the detection accuracy of naïve Bayesian classifier does not scale up as well as decision tree. It has been successfully tested in other problem domains that naïve Bayesian tree improves the classification rates in large dataset. In naïve Bayesian tree nodes contain and split as regular decision-trees, but the leaves contain naïve Bayesian classifiers. The experimental results on KDD99 benchmark network intrusion detection dataset demonstrate that this new approach scales up the detection rates for different attack types and reduces false positives in network intrusion detection.
Fichier principal
Vignette du fichier
DMF_ICDMKE_2010_p1.pdf (175.29 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00503961 , version 1 (19-07-2010)

Licence

Paternité

Identifiants

  • HAL Id : hal-00503961 , version 1

Citer

Dewan Md Farid, Huu Hoa Nguyen, Jérôme Darmont, Nouria Harbi, Mohammad Zahidur Rahman. Scaling up Detection Rates and Reducing False Positives in Intrusion Detection using NBTree. International Conference on Data Mining and Knowledge Engineering (ICDMKE 2010), 2010, Rome, Italy. pp.0. ⟨hal-00503961⟩
165 Consultations
242 Téléchargements

Partager

Gmail Facebook X LinkedIn More