Research Article
Network Anomaly Detection System with Optimized DS Evidence Theory
Table 10
Comparison of BP, DS with SBPA and ODS with RBPA for new attacks.
| Attack name | Total connections | Detected connections | DR (%) | BP | DS + SBPA | ODS + RBPA | BP | DS + SBPA | ODS + RBPA |
| Apache2 | 794 | 792 | 794 | 794 | 99.75 | 100.00 | 100.00 | httptunnel | 158 | 155 | 157 | 158 | 98.10 | 99.37 | 100.00 | mailbomb | 5000 | 4893 | 5000 | 500 | 97.86 | 100.00 | 100.00 | mscan | 1053 | 1050 | 1050 | 1052 | 99.72 | 99.72 | 99.91 | named | 17 | 16 | 17 | 17 | 94.12 | 100.00 | 100.00 | processtable | 759 | 758 | 759 | 759 | 99.87 | 100.00 | 100.00 | ps | 16 | 16 | 16 | 16 | 100.00 | 100.00 | 100.00 | saint | 736 | 736 | 735 | 736 | 100.00 | 99.86 | 100.00 | sendmail | 17 | 14 | 16 | 17 | 82.35 | 94.12 | 100.00 | snmpgetattack | 7741 | 7704 | 7716 | 7739 | 99.52 | 99.68 | 99.97 | snmpguess | 2406 | 2404 | 2404 | 2406 | 99.92 | 99.92 | 100.00 | sqlattack | 2 | 2 | 1 | 2 | 100.00 | 50.00 | 100.00 | udpstorm | 2 | 0 | 2 | 2 | 0.00 | 100.00 | 100.00 | worm | 2 | 2 | 2 | 2 | 100.00 | 100.00 | 100.00 | xlock | 9 | 7 | 6 | 8 | 77.78 | 66.67 | 88.89 | xsnoop | 4 | 3 | 4 | 4 | 75.00 | 100.00 | 100.00 | xterm | 13 | 13 | 13 | 13 | 100.00 | 100.00 | 100.00 |
| Average | 89.65 | 94.67 | 99.34 |
|
|