Show simple item record

dc.contributor.authorGitau, Joseph M.
dc.contributor.authorRodrigues, Anthony J.
dc.contributor.authorAbuonji, Paul
dc.date.accessioned2020-11-16T13:53:18Z
dc.date.available2020-11-16T13:53:18Z
dc.date.issued2020-07-06
dc.identifier.issn0975-0290
dc.identifier.urihttp://ir.jooust.ac.ke:8080/xmlui/handle/123456789/8863
dc.description.abstractThe maintenance of web server security is a daunting task today. Threats arise from hardware failures, software flaws, tentative probing and worst of all malicious attacks. Analysing server logs to detect suspicious activities is regarded as a key form of defence, however, their sheer size makes human log analysis challenging. Additionally, traditional intrusion detection systems rely on methods based on pattern-matching techniques which are not sustainable given the high rates at which new attack techniques are launched every day. The aim of this paper is to develop a proto-type intelligent log based intrusion detection system that can detect known and unknown intrusions automatically. Under a data mining framework, the intrusion detection system is trained with unsupervised learning algorithms specifically the k-means algorithm and the One Class SVM (Support Vector Machine) algorithm. The development of the prototype system is limited to machine generated logs due to lack of real access log files. However, the system’s development and implementation proved to be up to 85% accurate in detecting anomalous log patterns within the test logs. Keywords: prototype, intrusion detection, log-based, data mining.en_US
dc.language.isoenen_US
dc.publisherInt. J. Advanced Networking and Applicationsen_US
dc.subjectPrototypeen_US
dc.subjectIntrusion Detectionen_US
dc.subjectLog-baseden_US
dc.subjectData Miningen_US
dc.titlePrototype Intelligent Log-based Intrusion Detection Systemen_US
dc.typeArticleen_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record