GARUDA: Gaussian dissimilarity measure for feature representation and anomaly detection in Internet of things

被引:54
|
作者
Aljawarneh, Shadi A. [1 ]
Vangipuram, Radhakrishna [2 ]
机构
[1] Jordan Univ Sci & Technol, Irbid, Jordan
[2] VNR Vignana Jyothi Inst Engn & Technol, Ctr Excellence Networks & Secur, Dept Informat Technol, Hyderabad, India
来源
JOURNAL OF SUPERCOMPUTING | 2020年 / 76卷 / 06期
关键词
Anomaly detection; Feature representation; Intrusion; Dimensionality; Clustering; Distance measure; INTRUSION-DETECTION; SIMILARITY MEASURE; FEATURE-SELECTION; ALGORITHM; NETWORKS; TRENDS;
D O I
10.1007/s11227-018-2397-3
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The objective of any anomaly detection system is to efficiently detect several types of malicious traffic patterns that cannot be detected by conventional firewall systems. Designing an efficient intrusion detection system has three primary challenges that include addressing high dimensionality problem, choice of learning algorithm, and distance or similarity measure used to find the similarity value between any two traffic patterns or input observations. Feature representation and dimensionality reduction have been studied and addressed widely in the literature and have also been applied for the design of intrusion detection systems (IDS). The choice of classifiers is also studied and applied widely in the design of IDS. However, at the heart of IDS lies the choice of distance measure that is required for an IDS to judge an incoming observation as normal or abnormal. This challenge has been understudied and relatively less addressed in the research literature both from academia and from industry. This research aims at introducing a novel distance measure that can be used to perform feature clustering and feature representation for efficient intrusion detection. Recent studies such as CANN proposed feature reduction techniques for improving detection and accuracy rates of IDS that used Euclidean distance. However, accuracies of attack classes such as U2R and R2L are not significantly promising. Our approach GARUDA is based on clustering feature patterns incrementally and then representing features in different transformation space through using a novel fuzzy Gaussian dissimilarity measure. Experiments are conducted on both KDD and NSL-KDD datasets. The accuracy and detection rates of proposed approach are compared for classifiers such as kNN, J48, naive Bayes, along with CANN and CLAPP approaches. Experiment results proved that proposed approach resulted in the improved accuracy and detection rates for U2R and R2L attack classes when compared to other approaches.
引用
收藏
页码:4376 / 4413
页数:38
相关论文
共 50 条
  • [1] GARUDA: Gaussian dissimilarity measure for feature representation and anomaly detection in Internet of things
    Shadi A. Aljawarneh
    Radhakrishna Vangipuram
    The Journal of Supercomputing, 2020, 76 : 4376 - 4413
  • [2] A New Dissimilarity Measure for Trajectories with Applications in Anomaly Detection
    Espinosa-Isidron, Dustin L.
    Garcia-Reyes, Edel B.
    PROGRESS IN PATTERN RECOGNITION, IMAGE ANALYSIS, COMPUTER VISION, AND APPLICATIONS, 2010, 6419 : 193 - 201
  • [3] Anomaly traffic detection based on feature fluctuation for secure industrial internet of things
    Yin, Jie
    Zhang, Chuntang
    Xie, Wenwei
    Liang, Guangjun
    Zhang, Lanping
    Gui, Guan
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2023, 16 (04) : 1680 - 1695
  • [4] Anomaly traffic detection based on feature fluctuation for secure industrial internet of things
    Jie Yin
    Chuntang Zhang
    Wenwei Xie
    Guangjun Liang
    Lanping Zhang
    Guan Gui
    Peer-to-Peer Networking and Applications, 2023, 16 : 1680 - 1695
  • [5] Feature-Attended Federated LSTM for Anomaly Detection in the Financial Internet of Things
    Li, Yunlong
    Zhang, Rongguang
    Zhao, Pengcheng
    Wei, Yunkai
    APPLIED SCIENCES-BASEL, 2024, 14 (13):
  • [6] Anomaly Detection for Internet of Things Cyberattacks
    Alanazi, Manal
    Aljuhani, Ahamed
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (01): : 261 - 279
  • [7] Feature-Attended Multi-Flow LSTM for Anomaly Detection in Internet of Things
    Zou, Luhan
    Wei, Yunkai
    Ma, Lixiang
    Leng, Supeng
    IEEE INFOCOM 2022 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2022,
  • [8] Video Anomaly Detection and Localization Using Hierarchical Feature Representation and Gaussian Process Regression
    Cheng, Kai-Wen
    Chen, Yie-Tamg
    Fang, Wen-Hsien
    2015 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2015, : 2909 - 2917
  • [9] Anomaly Detection and Monitoring in Internet of Things Communication
    Stiawan, Deris
    Idris, Mohd. Yazid
    Malik, Reza Firsandaya
    Nurmaini, Siti
    Budiarto, Rahmat
    PROCEEDINGS OF 2016 8TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND ELECTRICAL ENGINEERING (ICITEE), 2016,
  • [10] Anomaly Detection in Aging Industrial Internet of Things
    Genge, Bela
    Haller, Piroska
    Enachescu, Calin
    IEEE ACCESS, 2019, 7 : 74217 - 74230