Data Mining for Network Intrusion Detection: How to Get Started
August 2001
Eric Bloedorn, The MITRE Corporation
Alan D. Christiansen, The MITRE Corporation
William Hill, The MITRE Corporation
Clement Skorupka, The MITRE Corporation
Lisa M. Talbot, The MITRE Corporation
Jonathan Tivel, The MITRE Corporation
ABSTRACT
Recently there has been much interest in applying data mining to computer network intrusion detection. For the past two years, MITRE has been exploring how to make data mining useful in this context. This paper provides lessons learned in this task. Based upon our experiences in getting started on this type of project, we suggest data mining techniques to consider and types of expertise and infrastructure needed. This paper has two intended audiences: network security professionals with little background in data mining, and data mining experts with little background in network intrusion detection.

Additional Search Keywords
data mining, intrusion detection, computer network security
|