Improvement of detection ability according to optimum selection of measures based on statistical approach

0Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A selection of useful measures and a generation of rules for detecting attacks from network data are very difficult. Expert's experiences are commonly required to generate the detection rules. If the rules are generated automatically, we will reduce man-power, management expense, and complexity of intrusion detection systems. In this paper, we propose two methods for generating the detection rules. One method is the statistical method based on relative entropy that uses for selecting the useful measures for generating the accurate rules. The other is decision tree algorithm based on entropy theory that generates the detection rules automatically. Also we propose a method of converting the continuous measures into categorical measures because continuous measures are hard to analyze. As the result, the detection rules for attacks are automatically generated without expert's experiences. Also, we selected the useful measures by the proposed method. © Springer-Verlag Berlin Heidelberg 2005.

Cite

CITATION STYLE

APA

Mun, G. J., Kim, Y. M., Kim, D. K., & Noh, B. N. (2005). Improvement of detection ability according to optimum selection of measures based on statistical approach. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 3822 LNCS, pp. 254–264). Springer Verlag. https://doi.org/10.1007/11599548_22

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free