• Home
  • Search
  • Bayesian event classification for intrusion detection
  • Cite Icon371
  • https://doi.org/10.1109/csac.2003.1254306Copy DOI Icon

Bayesian event classification for intrusion detection

  • Dec 8, 2003
  • C Kruegel +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Intrusion detection systems (IDSs) attempt to identify attacks by comparing collected data to predefined signatures known to be malicious (misuse-based IDSs) or to a model of legal behavior (anomaly-based IDSs). Anomaly-based approaches have the advantage of being able to detect previously unknown attacks, but they suffer from the difficulty of building robust models of acceptable behavior, which may result in a large number of false alarms. Almost all current anomaly-based intrusion detection systems classify an input event as normal or anomalous by analyzing its features, utilizing a number of different models. A decision for an input event is made by aggregating the results of all employed models. We have identified two reasons for the large number of false alarms, caused by incorrect classification of events in current systems. One is the simplistic aggregation of model outputs in the decision phase. Often, only the sum of the model results is calculated and compared to a threshold. The other reason is the lack of integration of additional information into the decision process. This additional information can be related to the models, such as the confidence in a model's output, or can be extracted from external sources. To mitigate these shortcomings, we propose an event classification scheme that is based on Bayesian networks. Bayesian networks improve the aggregation of different model outputs and allow one to seamlessly incorporate additional information. Experimental results show that the accuracy of the event classification process is significantly improved using our proposed approach.

Similar Papers
  • Conference Article
  • Citations8

Two Stratum Bayesian Network Based Anomaly Detection Model for Intrusion Detection System

  • Jan 01, 2008
  • Lu Huijuan +2
  • Book Chapter
  • Citations5

Developing an Intelligent Intrusion Detection and Prevention System against Web Application Malware

  • Jan 01, 2013
  • Ammar Alazab +3
  • Conference Article
  • Citations11

A grid-based clustering for low-overhead anomaly intrusion detection

  • Sep 01, 2011
  • Yang Zhong +2
  • Book Chapter
  • Citations14

Advanced Signature-Based Intrusion Detection System

  • Jul 20, 2022
  • Asma Shaikh +1
  • Conference Article
  • Citations30

Improvement in minority attack detection with skewness in network traffic

  • Mar 16, 2008
  • Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE
  • Ciza Thomas +1
  • Book Chapter
  • Citations9

Integrated Probabilistic Relevancy Classification (PRC) Scheme for Intrusion Detection in SCADA Network

  • Aug 11, 2019
  • S Shitharth +2
  • Conference Article
  • Citations5

Enhancing network intrusion detection systems with interval methods

  • Mar 13, 2005
  • Qiang Duan +2
  • PDF
  • Research Article
  • Citations8

Evaluating the impact of generative adversarial models on the performance of anomaly intrusion detection

  • Aug 28, 2023
  • IET Networks
  • Mohammad Arafah +2
  • Research Article
  • Citations8

Modified difference change detector for small targets in SAR imagery

  • Jan 01, 2008
  • IEEE Transactions on Aerospace and Electronic Systems
  • K.I Ranney +1
  • Single Book
  • Citations17

Understanding Intrusion Detection Through Visualization

  • Jan 01, 2006
  • Stefán Axelsson +1
  • Conference Article
  • Citations5

A Brief Analysis on Efficient Machine Learning Techniques for Intrusion Detection Model to Provide Network Security

  • Mar 23, 2023
  • Aswadhati Sirisha +1
  • Conference Article
  • Citations1

Biological inspired anomaly detection based on danger theory

  • May 01, 2013
  • Soudeh Behrozinia +3
  • Research Article

Improved Intrusion Detection System Using Discriminative learning Approach (A Review)

  • Jan 01, 2014
  • IOSR Journal of Computer Engineering
  • Charanjeet Kaur +1
  • Book Chapter
  • Citations8

Chapter 5 - Intrusion Prevention and Detection Systems

  • Jan 01, 2013
  • Managing Information Security
  • Christopher Day
  • Conference Article
  • Citations8

A Hybrid Intrusion Detection Method using Improved Stacking Ensemble Algorithm and False Positive Elimination Strategy for CBTC

  • Oct 08, 2022
  • Binyu Yin +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.