A Decision Tree Classifier for Intrusion Detection Priority Tagging

  • Ammar A
N/ACitations
Citations of this article
36Readers
Mendeley users who have this article in their library.

Abstract

Snort rule-checking is one of the most popular forms of Network Intrusion Detection Systems (NIDS). In this article, we show that Snort priorities of true positive traffic (real attacks) can be approximated in real-time, in the context of high speed networks, by a decision tree classifier, using the information of only three easily extracted features (protocol, source port, and destination port), with an accuracy of 99%. Snort issues alert priorities based on its own default set of attack classes (34 classes) that are used by the default set of rules it provides. But the decision tree model is able to predict the priorities without using this default classification. The obtained tagger can provide a useful complement to an anomaly detection intrusion detection system.

Cite

CITATION STYLE

APA

Ammar, A. (2015). A Decision Tree Classifier for Intrusion Detection Priority Tagging. Journal of Computer and Communications, 03(04), 52–58. https://doi.org/10.4236/jcc.2015.34006

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free