Since many current IDSs(Intrusion Detection Systems) are constructed by manual encoding of expert knowledge,updating of them are very slow and expensive.It is obvious that the frequent patterns mined from audit data can be used as reliable intrusion detection models.Aiming at this problem,this paper proposes an efficient parallel method to extract an extensive set of features that describe each network connection and learn frequent patterns that accurately capture the behavior of intrusions and normal activities,which are employed to facilitate model construction and incremental updates simply and easily.