Protocol Analysis in Intrusion Detection Using Decision Tree

  • Authors:
  • Tarek Abbes;Adel Bouhoula;Michaël Rusinowitch

  • Affiliations:
  • -;-;-

  • Venue:
  • ITCC '04 Proceedings of the International Conference on Information Technology: Coding and Computing (ITCC'04) Volume 2 - Volume 2
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Network based intrusion detection are the most deployedIDS. They frequently rely on signature matching detectionmethod and focus on the security of low level network protocols.Because of the large number of false positives fromone side, and the incapacity to detect some attack types fromanother side, IDS must allow more interest to the monitoringof application level protocols.We propose in this paper a combination of patternmatching and protocol analysis approaches. While the firstmethod of detection relies on a multipattern matching strategy,the second one benefits from an efficient decision treeadaptative to the network traffic characteristics.