Neural networks vs. decision trees for intrusion detection
نویسندگان
چکیده
Signature based intrusion detection systems cannot detect new attacks. These systems are the most used and developed ones. Current anomaly based intrusion detection systems are also unable to detect all kinds of new attacks because they are designed to restricted applications on limited environment. Current hackers are using new attacks where neither preventive techniques mainly based on access control nor current intrusion detection systems can prevent the devastating results of these attacks against information systems. We enhance the notion of anomaly detection and we use both neural networks and decision trees for intrusion detection. Since these techniques are mainly applicable to misuse detection, we use our anomaly detection enhancement and improve these techniques for anomaly detection. Experimental results demonstrate that while neural networks are highly successful in detecting known attacks, decision trees are more interesting to detect new attacks. The proposed methods outperform previous work in detecting both known and new attacks.
منابع مشابه
Proposing A Distributed Model For Intrusion Detection In Mobile Ad-Hoc Network Using Neural Fuzzy Interface
Security term in mobile ad hoc networks has several aspects because of the special specification of these networks. In this paper a distributed architecture was proposed in which each node performed intrusion detection based on its own and its neighbors’ data. Fuzzy-neural interface was used that is the composition of learning ability of neural network and fuzzy Ratiocination of fuzzy system as...
متن کاملProposing A Distributed Model For Intrusion Detection In Mobile Ad-Hoc Network Using Neural Fuzzy Interface
Security term in mobile ad hoc networks has several aspects because of the special specification of these networks. In this paper a distributed architecture was proposed in which each node performed intrusion detection based on its own and its neighbors’ data. Fuzzy-neural interface was used that is the composition of learning ability of neural network and fuzzy Ratiocination of fuzzy system as...
متن کاملFeature Set Reduction for Automatic Network Intrusion Detection with Machine Learning Algorithms
Selecting a minimum set of core features for automatic network intrusion detection with a variety of machine learning algorithms is a challenging problem. In this paper we propose a minimum feature set which can be easily extracted from network traffic. We compare decision trees, neural networks, naive Bayes and Bayesian networks classifiers performing on the KDDCup99 datasets. We show that by ...
متن کاملUsing Naïve Bayes Classifier to Accelerate Constructing Fuzzy Intrusion Detection Systems
453 AbstractA Bayesian classifier is one of the most widely used classifiers which possess several properties that make it surprisingly useful and accurate. It is illustrated that performance of Bayesian learning in some cases is comparable with neural networks and decision trees. Bayesian theorem suggests a straight forward process which is not based on search methods. This is the major point ...
متن کاملPhases vs. Levels using Decision Trees for Intrusion Detection Systems
Security of computers and the networks that connect them is increasingly becoming of great significance. Intrusion detection system is one of the security defense tools for computer networks. This paper compares two different model Approaches for representing intrusion detection system by using decision tree techniques. These approaches are Phase-model approach and Level-model approach. Each mo...
متن کامل