A Knowledge-Based System Implementation of Intrusion Detection Rules

  • Authors:
  • Eric Flior;Tychy Anaya;Cory Moody;Mohsen Beheshti;Jianchao Han;Kazimierz Kowalski

  • Affiliations:
  • -;-;-;-;-;-

  • Venue:
  • ITNG '10 Proceedings of the 2010 Seventh International Conference on Information Technology: New Generations
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

This research determines the feasibility of using an Exsys Corvid based expert system to detect and respond to network threats and appropriately administrate a Linux-based iptables firewall in real-time. In our implementation, we attempt to replace the human domain expert required for creating the expert system knowledge base with intrusion detection rules created by data-mining on network traffic. Our expert system will be used in conjunction with intrusion detection classification rules provided by the See5 data-mining tool, which have, in turn, been created based on the data fusion of normal and malicious network traffic from multiple network sensors.