A framework of cooperating intrusion detection based on clustering analysis and expert system

  • Authors:
  • De-gang Yang;Chun-yan Hu;Yong-hong Chen

  • Affiliations:
  • Normal University, Chongqing, China;Normal University, Chongqing, China;Normal University, Chongqing, China

  • Venue:
  • InfoSecu '04 Proceedings of the 3rd international conference on Information security
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper first analyzes and compares misuse detection and anomaly detection. Misuse detection can't detect new or unknown intrusion, while anomaly detection has the shortcoming on detection rate and false alarm rate. In order to overcome their respective shortcomings, we propose a framework of cooperating intrusion detection based on clustering analysis and expert system. It can meet the demand of real-time detection through clustering method and detect new or unknown intrusion. It integrates the virtues of both misuse detection and anomaly detection to improve the detection performance. Moreover it converts unknown intrusion to known intrusion, hence improves the detection accuracy and efficiency.