Master'sOpen Access

Veri madenciliği tekniklerini kullanarak ağ güvenliğinin kalitesinin iyileştirilmesi için ıds alertını geliştirme

2017
0 views
0 downloads
Advisor: Prof. Dr. Osman Nuri Uçan

Abstract (EN)

Intrusion-detection systems have become an increasingly important part of network security. Two types of intrusion detection systems are more common used, misuse and anomaly. Anomaly build a model of what is benign traffic, anything deviating from this will be flagged as malicious activity. Misuse search for pattern or known strings (signatures) within network traffic, any matching traffic will be considered suspicious. However, often normal network traffic produce matches against signatures, creating large amounts of false alarms. Data mining techniques looks for patterns or relations between records in a large data set. Frequent Itemset is a data mining technique to find frequently occurring items, in an alert generated. In this thesis applied Association Rules as data mining technique to find items of frequently occurring alarms. From these Itemsets we create rules, which provide ability to calculate the threat degree for all these items of each attribute and then extracts the threat degree of each alarms. The proposed system have been evaluated and tested by using DARPA '99 datasets. In this thesis, proposed a new system to eliminate the duplicate and redundant IDSs alert which result in minimizing the false positive rate. The proposed system is based on two major phases which each phase consists of several sub-phases. The first phase removes duplicated alerts by apply new filtering algorithm prepared for this purpose. The second phase is to reduce false alerts by eliminating the redundant alerts by apply association rules mining frequent itemsets algorithms. The proposed system is evaluated and tested by using five weeks of DARPA 1999 dataset. The results show that the proposed system significantly reduces the false positive alerts by 97.98%. These results demonstrate the system's high ability to reduce very large amounts of false alarms of intrusion detection systems. Keywords: Network Security, Intrusion Detection System, False Positive Alerts, Data Mining, Alert Evaluation, Threat Degree of Alerts.

Author

Dr. Isam Kareem Thajeel Thajeel

How to Cite

Isam Kareem Thajeel Thajeel (Master Thesis). Veri madenciliği tekniklerini kullanarak ağ güvenliğinin kalitesinin iyileştirilmesi için ıds alertını geliştirme, 2017, Altınbaş University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Altınbaş University