GARUDA: Gaussian dissimilarity measure for feature representation and anomaly detection in Internet of things

被引:54
|
作者
Aljawarneh, Shadi A. [1 ]
Vangipuram, Radhakrishna [2 ]
机构
[1] Jordan Univ Sci & Technol, Irbid, Jordan
[2] VNR Vignana Jyothi Inst Engn & Technol, Ctr Excellence Networks & Secur, Dept Informat Technol, Hyderabad, India
来源
JOURNAL OF SUPERCOMPUTING | 2020年 / 76卷 / 06期
关键词
Anomaly detection; Feature representation; Intrusion; Dimensionality; Clustering; Distance measure; INTRUSION-DETECTION; SIMILARITY MEASURE; FEATURE-SELECTION; ALGORITHM; NETWORKS; TRENDS;
D O I
10.1007/s11227-018-2397-3
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The objective of any anomaly detection system is to efficiently detect several types of malicious traffic patterns that cannot be detected by conventional firewall systems. Designing an efficient intrusion detection system has three primary challenges that include addressing high dimensionality problem, choice of learning algorithm, and distance or similarity measure used to find the similarity value between any two traffic patterns or input observations. Feature representation and dimensionality reduction have been studied and addressed widely in the literature and have also been applied for the design of intrusion detection systems (IDS). The choice of classifiers is also studied and applied widely in the design of IDS. However, at the heart of IDS lies the choice of distance measure that is required for an IDS to judge an incoming observation as normal or abnormal. This challenge has been understudied and relatively less addressed in the research literature both from academia and from industry. This research aims at introducing a novel distance measure that can be used to perform feature clustering and feature representation for efficient intrusion detection. Recent studies such as CANN proposed feature reduction techniques for improving detection and accuracy rates of IDS that used Euclidean distance. However, accuracies of attack classes such as U2R and R2L are not significantly promising. Our approach GARUDA is based on clustering feature patterns incrementally and then representing features in different transformation space through using a novel fuzzy Gaussian dissimilarity measure. Experiments are conducted on both KDD and NSL-KDD datasets. The accuracy and detection rates of proposed approach are compared for classifiers such as kNN, J48, naive Bayes, along with CANN and CLAPP approaches. Experiment results proved that proposed approach resulted in the improved accuracy and detection rates for U2R and R2L attack classes when compared to other approaches.
引用
收藏
页码:4376 / 4413
页数:38
相关论文
共 50 条
  • [31] A Generalized Approach for Anomaly Detection From the Internet of Moving Things
    Tian, Junfeng
    Ding, Wei
    Wu, Chunrui
    Nam, Kwang Woo
    IEEE ACCESS, 2019, 7 : 144972 - 144982
  • [32] MAD-IoT: Memory Anomaly Detection for the Internet of Things
    Myers, Jonathan
    Babun, Leonardo
    Yao, Edward
    Helble, Sarah
    Allen, Patrick
    2019 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2019,
  • [33] Application of hyperspectral image anomaly detection algorithm for Internet of things
    Wang, Xinjian
    Luo, Guangchun
    Tian, Ling
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (05) : 5155 - 5167
  • [34] POSTER: Decentralized Federated Learning for Internet of Things Anomaly Detection
    Lian, Zhuotao
    Su, Chunhua
    ASIA CCS'22: PROCEEDINGS OF THE 2022 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2022, : 1249 - 1251
  • [35] Distributed Internal Anomaly Detection System for Internet-of-Things
    Thanigaivelan, Nanda Kumar
    Nigussie, Ethiopia
    Kanth, Rajeev Kumar
    Virtanen, Seppo
    Isoaho, Jouni
    2016 13TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2016,
  • [36] An Intrusion Detection Scheme Based on Anomaly Mining in Internet of Things
    Fu, Rongrong
    Zheng, Kangfeng
    Zhang, Dongmei
    Yang, Yixian
    2011 IET 4TH INTERNATIONAL CONFERENCE ON WIRELESS, MOBILE & MULTIMEDIA NETWORKS (ICWMMN 2011), 2011, : 315 - 320
  • [37] Smart Audio Sensors in the Internet of Things Edge for Anomaly Detection
    Antonini, Mattia
    Vecchio, Massimo
    Antonelli, Fabio
    Ducange, Pietro
    Perera, Charith
    IEEE ACCESS, 2018, 6 : 67594 - 67610
  • [38] Sparse Representation With Gaussian Atoms and Its Use in Anomaly Detection
    Ilie-Ablachim, Denis C.
    Baltoiu, Andra
    Dumitrescu, Bogdan
    IEEE Open Journal of Signal Processing, 2024, 5 : 168 - 176
  • [39] Sparse Representation With Gaussian Atoms and Its Use in Anomaly Detection
    Ilie-Ablachim, Denis C.
    Baltoiu, Andra
    Dumitrescu, Bogdan
    IEEE OPEN JOURNAL OF SIGNAL PROCESSING, 2024, 5 : 168 - 176
  • [40] Anomaly Series Detection Algorithm Based on Segmentation Feature Representation
    Song, Chunlei
    Zhao, Xujun
    Gao, Yaxing
    Jin, Guangyin
    Computer Engineering and Applications, 2023, 59 (09) : 262 - 271