%0 Journal Article %T A Decision Tree Classifier for Intrusion Detection Priority Tagging %A Adel Ammar %J Journal of Computer and Communications %P 52-58 %@ 2327-5227 %D 2015 %I Scientific Research Publishing %R 10.4236/jcc.2015.34006 %X Snort rule-checking is one of the most popular forms of Network Intrusion Detection Systems (NIDS). In this article, we show that Snort priorities of true positive traffic (real attacks) can be approximated in real-time, in the context of high speed networks, by a decision tree classifier, using the information of only three easily extracted features (protocol, source port, and destination port), with an accuracy of 99%. Snort issues alert priorities based on its own default set of attack classes (34 classes) that are used by the default set of rules it provides. But the decision tree model is able to predict the priorities without using this default classification. The obtained tagger can provide a useful complement to an anomaly detection intrusion detection system. %K Intrusion Detection %K Network Security %K Snort %K Machine Learning %K Classification %K Decision Tree %U http://www.scirp.org/journal/PaperInformation.aspx?PaperID=55717