• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Design and Implementation of Sequential Pattern Miner to Analyze Alert Data Pattern


Moon-Sun Shin, Woo-Jin Paik, Journal of Internet Computing and Services, Vol. 10, No. 2, pp. 1-14, Apr. 2009
Full Text:
Keywords: alert data, IDS, sequential pattern mining, prefixSpan

Abstract

Intrusion detection is a process that identifies the attacks and responds to the malicious intrusion actions for the protection of the computer and the network resources. Due to the fast development of the Internet, the types of intrusions become more complex recently and need immediate and correct responses because the frequent occurrences of a new intrusion type rise rapidly. Therefore, to solve these problems of the intrusion detection systems, we propose a sequential pattern miner for analysis of the alert data in order to support intelligent and automatic detection of the intrusion. Sequential pattern mining is one of the methods to find the patterns among the extracted items that are frequent in the fixed sequences. We apply the prefixSpan algorithm to find out the alert sequences. This method can be used to predict the actions of the sequential patterns and to create the rules of the intrusions. In this paper, we propose an extended prefixSpan algorithm which is designed to consider the specific characteristics of the alert data. The extended sequential pattern miner will be used as a part of alert data analyzer of intrusion detection systems. By using the created rules from the sequential pattern miner, the HA(high-level alert analyzer) of PEP(policy enforcement point), usually called IDS, performs the prediction of the sequence behaviors and changing patterns that were not visibly checked.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Shin, M. & Paik, W. (2009). Design and Implementation of Sequential Pattern Miner to Analyze Alert Data Pattern. Journal of Internet Computing and Services, 10(2), 1-14.

[IEEE Style]
M. Shin and W. Paik, "Design and Implementation of Sequential Pattern Miner to Analyze Alert Data Pattern," Journal of Internet Computing and Services, vol. 10, no. 2, pp. 1-14, 2009.

[ACM Style]
Moon-Sun Shin and Woo-Jin Paik. 2009. Design and Implementation of Sequential Pattern Miner to Analyze Alert Data Pattern. Journal of Internet Computing and Services, 10, 2, (2009), 1-14.