首页> 外文期刊>Indian Journal of Science and Technology >Automatic Firewall Rule Generator for Network Intrusion Detection System based on Multiple Minimum Support
【24h】

Automatic Firewall Rule Generator for Network Intrusion Detection System based on Multiple Minimum Support

机译:基于多个最小支持的网络入侵检测系统自动防火墙规则生成器

获取原文
       

摘要

Background: Association rule mining plays a vital role in predicting the attacks and generating the firewall rules automatically. Data mining techniques discover the knowledge by counting the frequently occurring items, whereas most of the real-world datasets are non-uniform containing both frequently and relatively rarely occurring items. This paper discusses about how to generate the automatic firewall rules to detect anomalies using multiple minimum support. Methods: Mining association rules based on single minimum support approach suffers from the dilemma known as ‘rare item problem’ it requires multiple scans of database which increase the load and time consuming. To avoid this problem Multiple Minimum Support with Probability based approach (MMSP) is used to generate rules. Findings: To create a model of current user behavior from the dataset the probability will be compute with threshold value and the alarm will be raised accordingly. By using MMSP, the number of false alarm are reduced during intrusion detection and automatic firewall rules will be generated.
机译:背景:关联规则挖掘在预测攻击并自动生成防火墙规则方面起着至关重要的作用。数据挖掘技术通过对频繁发生的项目进行计数来发现知识,而大多数现实世界数据集都是不统一的,既包含频繁发生的项目也相对很少发生。本文讨论了如何使用多个最小支持来生成自动防火墙规则以检测异常。方法:基于单一最小支持方法的挖掘关联规则会遇到称为“稀有物品问题”的难题,它需要对数据库进行多次扫描,从而增加了工作量和时间。为了避免此问题,使用基于概率的多重最小支持方法(MMSP)生成规则。结果:要从数据集中创建当前用户行为的模型,将使用阈值计算概率,并相应地发出警报。通过使用MMSP,可以减少入侵检测过程中的虚假警报数量,并将生成自动防火墙规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号