Design of an intrusion detection system based on Bayesian networks

  • Authors:
  • Milan Tuba;Dusan Bulatovic

  • Affiliations:
  • Faculty of Computer Science, Megatrend University Belgrade, Serbia;Faculty of Computer Science, Megatrend University Belgrade, Serbia

  • Venue:
  • WSEAS Transactions on Computers
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

This paper describes a structure of a standalone Intrusion Detection System (IDS) based on a large Bayesian network. To implement the IDS we develop the design methodology of large Bayesian networks. A small number of natural templates (idioms) are defined which make the design of Bayesian network easier. They are related to specific fragments of Bayesian networks representing the basic elements in reasoning about uncertain events. The idioms represent the graphical structure, without the probabilistic tables. The use of idioms speeds-up the development of Bayesian networks and improves their quality. Example network is constructed and examined. Such Bayesian network can represent an independent agent in a distributed system. Results are promising since with very limited computation and low sensitivity to the quality of prior knowledge, potentially dangerous situations are successfully detected and classified.