A Real-Time Intrusion Detection Algorithm for Network Security

被引:0
|
作者
El-Bakry, Hazem M. [1 ]
Mastorakis, Nikos [2 ]
机构
[1] Mansoura Univ, Fac Comp Sci & Informat Syst, Mansoura, Egypt
[2] MIUE, Hellenic Naval Acad, Dept Comp Sci, Piraeus, Greece
关键词
Fast Intrusion Detection; Clustering; Data Mining; E-Government; Cross correlation; Frequency domain; Neural Networks;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
E-government is an important issue which integrates existing local area networks into a global network that provide many services to the nation citizens. This network: requires a strong security infrastructure to guarantee the confidentiality of national data and the availability of government services. In this paper, a framework for network intrusion detection systems is presented. Such framework utilizes data mining techniques and is customized for the E-Government Network (EGN). It consists of two phases: an offline phase in which the intrusion detection system learns the normal usage profiles for each local network domain, and a real time intrusion detection phase. In the real time phase, known attacks are detected at a global layer at the EGN perimeters while normal behavior is filtered out at a local layer defined for each LAN domain. Clustering is used to focus the analysis on the remaining suspicious activity and identify whether it represents new intrusive or normal behavior. This framework is intended to detect intrusions in real-time, achieve low false alarm rates, and continuously adapt to the environment changes and emergence of new behavior. This research is a development for the work presented in [22,23]. The main achievement of this paper is the fast attack detection algorithm. Such algorithm based on performing cross correlation in the frequency domain between data traffic and the input weights of fast time delay neural networks (FTDNNs). It is proved mathematically and practically that the number of computation steps required for the presented FTDNNs is less than that needed by conventional time delay neural networks (CTDNNs). Simulation results using MATLAB confirm the theoretical computations.
引用
下载
收藏
页码:533 / +
页数:3
相关论文
共 50 条
  • [41] A Bayesian classification model for real-time intrusion detection
    Puttini, RS
    Marrakchi, Z
    Mé, L
    BAYESIAN INFERENCE AND MAXIMUM ENTROPY METHODS IN SCIENCE AND ENGINEERING, 2003, 659 : 150 - 162
  • [42] Performance adaptation in real-time intrusion detection systems
    Lee, W
    Cabrera, JBD
    Thomas, A
    Balwalli, N
    Saluja, S
    Zhang, Y
    RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS, 2002, 2516 : 252 - 273
  • [43] Fuzzy frequent episodes for real-time intrusion detection
    Luo, JX
    Bridges, SM
    Vaughn, RB
    10TH IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS, VOLS 1-3: MEETING THE GRAND CHALLENGE: MACHINES THAT SERVE PEOPLE, 2001, : 368 - 371
  • [44] Real-time intrusion detection and suppression in ATM networks
    Bettati, R
    Zhao, W
    Teodor, D
    PROCEEDINGS OF THE WORKSHOP ON INTRUSION DETECTION AND NETWORK MONITORING (ID '99), 1999, : 111 - 118
  • [45] Real-Time Intrusion Detection in Power System Operations
    Valenzuela, Jorge
    Wang, Jianhui
    Bissinger, Nancy
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2013, 28 (02) : 1052 - 1062
  • [46] Meta learning intrusion detection in real time network
    Bie, Rongfang
    Jin, Xin
    Chen, Chuanliang
    Xu, Chuan
    Huang, Ronghuai
    ARTIFICIAL NEURAL NETWORKS - ICANN 2007, PT 1, PROCEEDINGS, 2007, 4668 : 809 - +
  • [47] Real-time correlation of network security alerts
    Li, Zhitang
    Zhang, Aifang
    Lei, Jie
    Wang, Li
    ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 73 - +
  • [48] REAL-TIME DETECTION BY A STATISTICAL ALGORITHM
    BURGHARDT, T
    SAVIN, IV
    PHYSICS OF THE EARTH AND PLANETARY INTERIORS, 1992, 69 (3-4) : 322 - 329
  • [49] A REAL-TIME QRS DETECTION ALGORITHM
    PAN, J
    TOMPKINS, WJ
    IEEE TRANSACTIONS ON BIOMEDICAL ENGINEERING, 1985, 32 (03) : 230 - 236
  • [50] Real-time Intrusion Prevention and Security Analysis of Networks using HMMs
    Haslum, Kjetil
    Moe, Marie E. G.
    Knapskog, Svein J.
    2008 IEEE 33RD CONFERENCE ON LOCAL COMPUTER NETWORKS, VOLS 1 AND 2, 2008, : 902 - 909