Network intrusion detection and classification with decision tree and rule based approaches

  • Authors:
  • Thanvarat Komviriyavut;Phurivit Sangkatsanee;Naruemon Wattanapongsakorn;Chalermpol Charnsripinyo

  • Affiliations:
  • Department of Computer Engineering, King Mongkut's University of Technology Thonburi, Bangkok, Thailand;Department of Computer Engineering, King Mongkut's University of Technology Thonburi, Bangkok, Thailand;Department of Computer Engineering, King Mongkut's University of Technology Thonburi, Bangkok, Thailand;Network Technology Laboratory, National Electronics and Computer Technology Center, Klong Luang, Pathumthani, Thailand

  • Venue:
  • ISCIT'09 Proceedings of the 9th international conference on Communications and information technologies
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Together with the extensive deployment of computer networks, the number of network attacks is greatly increasing. These attacks affect to availability and quality of services of the networks as well as confidentiality of private or important information data. In this paper, we present two network intrusion detection (IDS) techniques which are C4.S Decision Tree and Ripper rules to assess and test an online dataset (RLD09 dataset). The dataset was collected from actual environment and then preprocessed to have only 13 features which are much simpler than existing traditional dataset such as KDD99 with 41 features. Thus, the RLD09 dataset features can provide real-time detection speed with low memory and CPU consumption. Our IDSs can classify the network data into classes which are normal data, Denial of Service (DoS) attack, and Probe (Port Scanning) attack. Our IDS techniques give the detection rates higher than 98%. Furthermore, they can detect unknown or new attacks, where the C4.S Decision Tree detection rate is about the double of the Ripper rule detection rate. These tests can prove that our techniques are effective in detecting and classifying the new unknown attacks in the real environment.