바로가기메뉴

본문 바로가기 주메뉴 바로가기

A New Association Rule Mining based on Coverage and Exclusion for Network Intrusion Detection

Journal of The Korea Internet of Things Society / Journal of The Korea Internet of Things Society, (P)2799-4791;
2023, v.9 no.1, pp.77-87
https://doi.org/https://doi.org/10.20465/kiots.2023.9.1.077



Abstract

Applying various association rule mining algorithms to the network intrusion detection task involves two critical issues: too large size of generated rule set which is hard to be utilized for IoT systems and hardness of control of false negative/positive rates. In this research, we propose an association rule mining algorithm based on the newly defined measures called coverage and exclusion. Coverage shows how frequently a pattern is discovered among the transactions of a class and exclusion does how frequently a pattern is not discovered in the transactions of the other classes. We compare our algorithm experimentally with the Apriori algorithm which is the most famous algorithm using the public dataset called KDDcup99. Compared to Apriori, the proposed algorithm reduces the resulting rule set size by up to 93.2 percent while keeping accuracy completely. The proposed algorithm also controls perfectly the false negative/positive rates of the generated rules by parameters. Therefore, network analysts can effectively apply the proposed association rule mining to the network intrusion detection task by solving two issues.

keywords
네트워크 침입 탐지, 연관 규칙 마이닝, 척도, Network Intrusion Detection, Association Rule Mining, Measure

Journal of The Korea Internet of Things Society