期刊名称:International Journal of Computer Science and Network Security
印刷版ISSN:1738-7906
出版年度:2011
卷号:11
期号:9
页码:39-46
出版社:International Journal of Computer Science and Network Security
摘要:Fuzzy clustering technique and Dempster-Shafer theory both have merit of resolving the uncertainty problems raised by limited and ambiguous information or data during a decision process. Also, the k-NN technique is applied to speed up the detection process. Intrusion detection in fact is a classification task that classifies network traffics into normal usage category or attack category. In our work, the main goal is to identify U2R and R2L attacks from the KDD99 intrusion detection benchmark data set. For successfully achieving the goal, we divide the development of an intrusion detection system into two phases: training phase and classification phase. In the training phase, decision rules are generated in accordance with the clustering result of provided training data. The rules are used for classifying future network traffic whether is a normal activity or an attack in the classification phase.