Real-Time Network Intrusion Prevention System Using Incremental Feature Generation

被引:1
|
作者
Uhm, Yeongje [1 ]
Pak, Wooguil [2 ]
机构
[1] Yeungnam Univ, Res & Business Dev Fdn, Gyongsan 38541, Gyeongbuk, South Korea
[2] Yeungnam Univ, Dept Informat & Commun Engn, Gyongsan 38541, Gyeongbuk, South Korea
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2022年 / 70卷 / 01期
关键词
Network intrusion detection; network intrusion prevention; real-time; two-level classifier; DEEP LEARNING APPROACH; DECISION TREES; RANDOM FOREST;
D O I
10.32604/cmc.2022.019667
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security measures are urgently required to mitigate the recent rapid increase in network security attacks. Although methods employing machine learning have been researched and developed to detect various network attacks effectively, these are passive approaches that cannot protect the network from attacks, but detect them after the end of the session. Since such passive approaches cannot provide fundamental security solutions, we propose an active approach that can prevent further damage by detecting and block-ing attacks in real time before the session ends. The proposed technology uses a two-level classifier structure: the first-stage classifier supports real-time classification, and the second-stage classifier supports accurate classification. Thus, the proposed approach can be used to determine whether an attack has occurred with high accuracy, even under heavy traffic. Through extensive evaluation, we confirm that our approach can provide a high detection rate in real time. Furthermore, because the proposed approach is fast, light, and easy to implement, it can be adopted in most existing network security equip-ment. Finally, we hope to mitigate the limitations of existing security systems, and expect to keep networks faster and safer from the increasing number of cyber-attacks.
引用
收藏
页码:1631 / 1648
页数:18
相关论文
共 50 条
  • [1] Integrated Feature-Based Network Intrusion Detection System Using Incremental Feature Generation
    Kim, Taehoon
    Pak, Wooguil
    [J]. ELECTRONICS, 2023, 12 (07)
  • [2] A real-time Network Intrusion Detection System based on incremental mining approach
    Su, Ming-Yang
    Chang, Kai-Chi
    Wei, Hua-Fu
    Lin, Chun-Yuen
    [J]. ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2008, : 179 - +
  • [3] Real-Time Network Intrusion Prevention System Based on Hybrid Machine Learning
    Seo, Wooseok
    Pak, Wooguil
    [J]. IEEE ACCESS, 2021, 9 : 46386 - 46397
  • [4] REAL-TIME TRAFFIC DETECTION and ANALYSIS of NETWORK SECURITY INTRUSION ATTACK: SNORT INTRUSION PREVENTION SYSTEM
    Zhou, A.L.
    [J]. Telecommunications and Radio Engineering (English translation of Elektrosvyaz and Radiotekhnika), 2020, 79 (12): : 1055 - 1062
  • [5] Using Incremental Mining to Generate Fuzzy Rules for Real-Time Network Intrusion Detection Systems
    Su, Ming-Yang
    Yeh, Sheng-Cheng
    Chang, Kai-Chi
    Wei, Hua-Fu
    [J]. 2008 22ND INTERNATIONAL WORKSHOPS ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOLS 1-3, 2008, : 50 - 55
  • [6] Feature weighting and selection for a real-time network intrusion detection system based on GA with KNN
    Su, Ming-Yang
    Chang, Kai-Chi
    Wei, Hua-Fu
    Lin, Chun-Yuen
    [J]. INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2008, 5075 : 195 - 204
  • [7] An optimal feature based network intrusion detection system using bagging ensemble method for real-time traffic analysis
    Chowdhury, Ratul
    Sen, Shibaprasad
    Roy, Arindam
    Saha, Banani
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (28) : 41225 - 41247
  • [8] An optimal feature based network intrusion detection system using bagging ensemble method for real-time traffic analysis
    Ratul Chowdhury
    Shibaprasad Sen
    Arindam Roy
    Banani Saha
    [J]. Multimedia Tools and Applications, 2022, 81 : 41225 - 41247
  • [9] Improved Real-Time Discretize Network Intrusion Detection System
    Eid, Heba F.
    Azar, Ahmad Taher
    Hassanien, Aboul Ella
    [J]. PROCEEDINGS OF SEVENTH INTERNATIONAL CONFERENCE ON BIO-INSPIRED COMPUTING: THEORIES AND APPLICATIONS (BIC-TA 2012), VOL 1, 2013, 201 : 99 - +
  • [10] A real-time network intrusion detection system for large-scale attacks based on an incremental mining approach
    Su, Ming-Yang
    Yu, Gwo-Jong
    Lin, Chun-Yuen
    [J]. COMPUTERS & SECURITY, 2009, 28 (05) : 301 - 309