Towards Integrating Data Mining with Knowledge Based System: The Case of Network Intrusion detection

dc.contributor.advisorMeshesha, Million (PhD)
dc.contributor.authorMohammed, Abdulkerim
dc.date.accessioned2018-11-23T12:29:01Z
dc.date.accessioned2023-11-29T04:57:17Z
dc.date.available2018-11-23T12:29:01Z
dc.date.available2023-11-29T04:57:17Z
dc.date.issued2013-06
dc.description.abstractNetwork intrusion is one of cyber attacks which bypass the security mechanisms of computer systems. Protection of such types of attacks ensures organizations from unplanned shut down of networks which have otherwise bad consequent on the organization. Intrusion detection systems respond to malicious activities. Misuse detection searches for patterns or user behaviors that match known intrusion scenarios, which are stored as signatures. Anomaly detection keeps normal behavior of network and it label as an attack behaviors which are beyond this. Data mining has been used for intrusion detection systems due to the fact that they are generally more precise and require far less manual processing and input from human experts. But researches which employed data mining for intrusion detection merely generate patterns and they lack in utilizing the knowledge. In this study, rule based intrusion detection and advising knowledge based system is proposed. The system is aiming at utilizing hidden knowledge extracted by employing induction algorithm of data mining, specifically JRip from sampled KDDcup‘99 intrusion data set. The integrator application then links the model created by JRip classifier to knowledge based system so as to add knowledge automatically. In doing so, the integrator understands the syntax of JRip classifier and PROLOG and converts from rule representation in JRip to PROLOG understandable format. Finally, the performance of the system is evaluated by preparing test cases. Twenty test cases are prepared for system performance test and provided to domain experts. For user acceptance test users are trained and evaluated the system. Generally the system has scored 80.5% overall performance which is a promising result. But further exploration has to be done to refine the knowledge base and boost the advantages of integrating data mining induced knowledge with knowledge based system. Keywords:- Intrusion detection, data mining, knowledge based system, Integratoren_US
dc.identifier.urihttp://etd.aau.edu.et/handle/123456789/14454
dc.language.isoenen_US
dc.publisherAddis Ababa Universityen_US
dc.subjectIntrusion detectionen_US
dc.subjectdata mining,en_US
dc.subjectknowledge based systemen_US
dc.subjectIntegratoren_US
dc.titleTowards Integrating Data Mining with Knowledge Based System: The Case of Network Intrusion detectionen_US
dc.typeThesisen_US

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Abdulkerim Mohammed.pdf
Size:
2.26 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description: