Tongxin xuebao (Jan 2005)
Research on intrusion detection system based on two-level algorithm
Abstract
To the limitation of current intrusion detection models, an idea of formulating an intrusion detection model system (TAIDS) based on the GMTH Two-level algorithm was presented. With the joint of two-level algorithm and GMDH multi-stage iterate method, TAIDS would construct models simultaneously with data from different time range, which could enlarge the time range of the detected intrusive behavior. Through the analysis of the target system, relations between influential factors in intrusion were searched and an optimal model was built, which would decrease the false retrieval and fallout ratio efficiently. System framework and model algorithm were given also. This model system is proved to be effective from the comparison of emulating experiments on Snort and NIDES detection system.