Publication | Closed Access
Naive Bayes vs decision trees in intrusion detection systems
473
Citations
9
References
2004
Year
Unknown Venue
Anomaly DetectionMachine LearningEngineeringInformation SecurityIntrusion Detection SystemsHardware SecurityData ScienceData MiningPattern RecognitionDecision TreeDecision Tree LearningBayes NetworksIntrusion Detection SystemThreat DetectionNaive BayesKnowledge DiscoveryComputer ScienceAttack GraphData SecurityIntrusion Detection
Bayes networks are powerful tools for decision and reasoning under uncertainty. A very simple form of Bayes networks is called naive Bayes, which are particularly efficient for inference tasks. However, naive Bayes are based on a very strong independence assumption. This paper offers an experimental study of the use of naive Bayes in intrusion detection. We show that even if having a simple structure, naive Bayes provide very competitive results. The experimental study is done on KDD'99 intrusion data sets. We consider three levels of attack granularities depending on whether dealing with whole attacks, or grouping them in four main categories or just focusing on normal and abnormal behaviours. In the whole experimentations, we compare the performance of naive Bayes networks with one of well known machine learning techniques which is decision tree. Moreover, we compare the good performance of Bayes nets with respect to existing best results performed on KDD'99.
| Year | Citations | |
|---|---|---|
Page 1
Page 1