Fusion of Misuse Detection with Anomaly Detection Technique for Novel Hybrid Network Intrusion Detection System

被引:3
|
作者
Hussain, Jamal [1 ]
Lalmuanawma, Samuel [1 ]
机构
[1] Mizoram Univ, Math & Comp Sci Dept, Aizawl 796004, Mizoram, India
关键词
Hybrid IDS; Feature selection; Naive Bayes classifier; Decision tree; One-class SVM; FEATURE-SELECTION; SUPPORT;
D O I
10.1007/978-981-10-3779-5_10
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intrusion detection system (IDS) was designed to monitor the abnormal activity occurring in the computer network system. Many researchers concentrate their efforts on designing different techniques to build reliable IDS. However, individual technique such as misuse and anomaly techniques alone failed to provide the best possible detection rate. In this paper, we proposed a new hybrid IDS model with feature selection that integrates misuse detection technique and anomaly detection technique based on a decision rule structure. The key idea was to take the advantage of naive Bayes (NB) feature selection, misuse detection technique based on decision tree (DT), and anomaly detection based on one-class support vector machine (OCSVM). First, misuse detection is built using single DT algorithm where the training data get decomposed into multiple subsets with the help of decision rules. Then, anomaly detection models are created for each decomposed subset based on multiple OCSVM. In the proposed model, NB and DT can find the best-selected features to ameliorate the detection accuracy by obtaining decision rules for known normal and attack anomalies. Then, the OCSVM can detect new attacks that result in an improvement in the detection accuracy of classification. The proposed new hybrid model was evaluated based on the NSL-KDD data sets, which is an upgraded version of KDD99 data set developed by DARPA. Simulation results demonstrate that the proposed hybrid model outperforms conventional models in terms of time complexity and detection rate with the much lower rate of false positives.
引用
收藏
页码:73 / 87
页数:15
相关论文
共 50 条
  • [31] Hybrid Intrusion Detection System using an Unsupervised method for Anomaly-based Detection
    Bhadauria, Saumya
    Mohanty, Tamanna
    2021 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (IEEE ANTS), 2021,
  • [32] Anomaly Based Network Intrusion Detection with Unsupervised Outlier Detection
    Zhang, Jiong
    Zulkernine, Mohammad
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2388 - 2393
  • [33] A comparative study of anomaly detection schemes in network intrusion detection
    Lazarevic, A
    Ertoz, L
    Kumar, V
    Ozgur, A
    Srivastava, J
    PROCEEDINGS OF THE THIRD SIAM INTERNATIONAL CONFERENCE ON DATA MINING, 2003, : 25 - 36
  • [34] Hybrid Network Intrusion Detection
    Tahmoush, David
    SENSORS, AND COMMAND, CONTROL, COMMUNICATIONS, AND INTELLIGENCE (C3I) TECHNOLOGIES FOR HOMELAND SECURITY AND HOMELAND DEFENSE XIII, 2014, 9074
  • [35] Network Intrusion Anomaly Detection Model Based on Multiclassifier Fusion Technology
    Hang F.
    Guo W.
    Chen H.
    Xie L.
    Bai X.
    Liu Y.
    Mobile Information Systems, 2023, 2023
  • [36] An Efficient Hybrid Classifier Model for Anomaly Intrusion Detection System
    Shah, Asghar Ali
    Ehsan, M. Khurram
    Ishaq, Kashif
    Ali, Zakir
    Farooq, Muhammad Shoaib
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2018, 18 (11): : 127 - +
  • [37] Two Stratum Bayesian Network Based Anomaly Detection Model for Intrusion Detection System
    Lu Huijuan
    Chen Jianguo
    Wei Wei
    PROCEEDINGS OF THE INTERNATIONAL SYMPOSIUM ON ELECTRONIC COMMERCE AND SECURITY, 2008, : 482 - 487
  • [38] A two-stage hybrid classification technique for network intrusion detection system
    Jamal Hussain
    Samuel Lalmuanawma
    Lalrinfela Chhakchhuak
    International Journal of Computational Intelligence Systems, 2016, 9 : 863 - 875
  • [39] A two-stage hybrid classification technique for network intrusion detection system
    Hussain, Jamal
    Lalmuanawma, Samuel
    Chhakchhuak, Lalrinfela
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2016, 9 (05) : 863 - 875
  • [40] HYBRID MACHINE LEARNING TECHNIQUE FOR INTRUSION DETECTION SYSTEM
    Tahir, Hatim Mohamad
    Hasan, Wael
    Said, Abas Md
    Zakaria, Nur Haryani
    Katuk, Norliza
    Kabir, Nur Farzana
    Omar, Mohd Hasbullah
    Ghazali, Osman
    Yahya, Noor Izzah
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS, 2015, : 464 - 472