>
Fa   |   Ar   |   En
   Improving intrusion detection system based on snort rules for network probe attacks detection with association rules technique of data mining  
   
نویسنده khamphakdee n. ,benjamas n. ,saiyod s.
منبع journal of ict research and applications - 2015 - دوره : 8 - شماره : 3 - صفحه:234 -250
چکیده    The intrusion detection system (ids) is an important network security tool for securing computer and network systems. it is able to detect and monitor network traffic data. snort ids is an open-source network security tool. it can search and match rules with network traffic data in order to detect attacks,and generate an alert. however,the snort ids can detect only known attacks. therefore,we have proposed a procedure for improving snort ids rules,based on the association rules data mining technique for detection of network probe attacks. we employed the mit-darpa 1999 data set for the experimental evaluation. since behavior pattern traffic data are both normal and abnormal,the abnormal behavior data is detected by way of the snort ids. the experimental results showed that the proposed snort ids rules,based on data mining detection of network probe attacks,proved more efficient than the original snort ids rules,as well as icmp.rules and icmp-info.rules of snort ids. the suitable parameters for the proposed snort ids rules are defined as follows: min_sup set to 10%,and min_conf set to 100%,and through the application of eight variable attributes. as more suitable parameters are applied,higher accuracy is achieved. © 2015 published by itb journal publisher.
کلیدواژه Apriori algorithm; Data mining; Intrusion detection system; Network probe attack; Network security; Snort IDS rules
آدرس advanced smart computing laboratory,department of computer science,khon kaen university,123 moo 16 mittapap rd.,nai-muang,muang district, Thailand, advanced smart computing laboratory,department of computer science,khon kaen university,123 moo 16 mittapap rd.,nai-muang,muang district, Thailand, hardware-human interface and communications laboratory,department of computer science,khon kaen university,123 moo 16 mittapap rd.,nai-muang,muang district, Thailand
 
     
   
Authors
  
 
 

Copyright 2023
Islamic World Science Citation Center
All Rights Reserved