Adaptive anomaly-based intrusion detection system using genetic algorithm and profiling

被引:34
|
作者
Alves Resende, Paulo Angelo [1 ]
Drummond, Andre Costa [1 ]
机构
[1] Univ Brasilia, Dept Comp Sci, Brasilia, DF, Brazil
来源
SECURITY AND PRIVACY | 2018年 / 1卷 / 04期
关键词
adaptive intrusion detection systems; anomaly-based intrusion detection; apache spark; machine learning; profiling; projected clustering;
D O I
10.1002/spy2.36
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection systems have been playing an important role in defeating treats in the Cyberspace. In this context, researchers have been proposing anomaly-based methods for intrusion detection, on which the "normal" behavior is defined and the deviations (anomalies) are pointed out as intrusions. In this case, profiling is a relevant procedure used to establish a baseline for the normal behavior. In this work, an adaptive approach based on genetic algorithm is used to select features for profiling and parameters for anomaly-based intrusion detection methods. Additionally, two anomaly-based methods are introduced to be coupled with the proposed approach. One is based on basic statistics and the other is based on a projected clustering procedure. In the presented experiments performed on the CICIDS2017 dataset, our methods achieved results as good as detection rate equals to 92.85% and false positive rate of 0.69%. The presented approach iteratively adapts to new attacks and to the environmental requirements, such as security staff's preferences and available computational resources.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] An Anomaly-based Intrusion Detection System Using Butterfly Optimization Algorithm
    Mahboob, Amir Soltany
    Moghaddam, Mohammad Reza Ostadi
    [J]. 2020 6TH IRANIAN CONFERENCE ON SIGNAL PROCESSING AND INTELLIGENT SYSTEMS (ICSPIS), 2020,
  • [2] Anomaly-Based Network Intrusion Detection System
    Villalba, L. J. G.
    Orozco, A. L. S.
    Vidal, J. M.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (03) : 850 - 855
  • [3] An Adaptive Anomaly-based Intrusion Prevention System for Databases
    Emrick, Eric S.
    Hu, Yi
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC), 2014, : 3382 - 3389
  • [4] Anomaly-Based Intrusion Detection System Using Support Vector Machine
    Krishnaveni, S.
    Vigneshwar, Palani
    Kishore, S.
    Jothi, B.
    Sivamohan, S.
    [J]. ARTIFICIAL INTELLIGENCE AND EVOLUTIONARY COMPUTATIONS IN ENGINEERING SYSTEMS, 2020, 1056 : 723 - 731
  • [5] Hybrid Intrusion Detection System using an Unsupervised method for Anomaly-based Detection
    Bhadauria, Saumya
    Mohanty, Tamanna
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (IEEE ANTS), 2021,
  • [6] An anomaly-based Network Intrusion Detection System using Deep learning
    Nguyen Thanh Van
    Tran Ngoc Thinh
    Le Thanh Sach
    [J]. 2017 INTERNATIONAL CONFERENCE ON SYSTEM SCIENCE AND ENGINEERING (ICSSE), 2017, : 210 - 214
  • [7] Undermining an anomaly-based intrusion detection system using common exploits
    Tan, KMC
    Killourhy, KS
    Maxion, RA
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS, 2002, 2516 : 54 - 73
  • [8] An Adaptive Threshold Method for Anomaly-based Intrusion Detection Systems
    Chae, Younghun
    Katenka, Natallia
    DiPippo, Lisa
    [J]. 2019 IEEE 18TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2019, : 221 - 224
  • [9] SCADA Networks Anomaly-based Intrusion Detection System
    Almehmadi, Abdulaziz
    [J]. 11TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN 2018), 2018,
  • [10] Anomaly-based intrusion detection system for IoT application
    Bhavsar M.
    Roy K.
    Kelly J.
    Olusola O.
    [J]. Discover Internet of Things, 2023, 3 (01):