Title :
A Network-Based Internet Worm Intrusion Detection and Prevention System
Author :
Wattanapongsakorn, Naruemon ; Wonghirunsombat, E. ; Assawaniwed, T. ; Hanchana, V. ; Srakaew, S. ; Charnsripinyo, C.
Author_Institution :
Dept. of Comput. Eng., King Mongkut´s Univ. of Technol. Thonburi, Bangkok, Thailand
Abstract :
Many incidents of network attacks and security threats have been previously reported. Damages caused by network attacks and malware tend to be high. In this paper, we present a network-based Intrusion Detection and Prevention System (IDPS), which can detect network attacks and Internet Worms. The proposed system can immediately classify network attack types (i.e. DoS, Probe) and Internet worm from normal network traffic by using traffic classification technique and selected well-known machine learning algorithms (i.e. Decision TreeC4.5, Random Forest, Ripple Rule, Bayesian Network, Back Propagation Neural Network) in both standalone mode and distributed mode. The proposed IDPS also allows system administrator to update existing rule sets or learn new trained data sets with a user-friendly graphic user interface. In our experiments, we can correctly detect and prevent network attacks with high accuracy, more than 99%.
Keywords :
Bayes methods; Internet; computer network security; decision trees; graphical user interfaces; invasive software; learning (artificial intelligence); random processes; telecommunication computing; telecommunication traffic; Bayesian network; Decision TreeC4.5; IDPS; back propagation neural network; machine learning algorithms; network attack prevention; network attack type classification; network security threats; network traffic classification technique; network-based Internet worm intrusion detection and prevention system; random forest; ripple rule; user-friendly graphic user interface; Computers; Grippers; Internet; Intrusion detection; Machine learning algorithms; Probes; Servers;
Conference_Titel :
IT Convergence and Security (ICITCS), 2013 International Conference on
Conference_Location :
Macao
DOI :
10.1109/ICITCS.2013.6717779