Evolutive Modeling of TCP/IP Network Traffic for Intrusion Detection

The detection of intrusions over computer networks can be cast to the task of detecting anomalous patterns of network traffic. In this case, patterns of normal traffic have to be determined and compared against the current network traffic. Data mining systems based on Genetic Algorithms can contribute powerful search techniques for the acquisition of patterns of the network traffic from the large amount of data made available by audit tools. In this paper we compare models of data traffic acquired by a system based on a distributed genetic algorithm with the ones acquired by a systembased on greedy heuristics. Also we discuss representation change of the network data and its impact over the performances of the traffic models.