Adaptive intrusion detection via GA-GOGMM-based pattern learning with fuzzy rough set-based attribute selection

被引:29
|
作者
Liu, Jinping [1 ]
Zhang, Wuxia [1 ]
Tang, Zhaohui [3 ]
Xie, Yongfang [3 ]
Ma, Tianyu [2 ]
Zhang, Jingjing [1 ]
Zhang, Guoyong [3 ]
Niyoyita, Jean Paul [4 ]
机构
[1] Hunan Normal Univ, Hunan Prov Key Lab Intelligent Comp & Language In, Changsha 410081, Hunan, Peoples R China
[2] Hunan Normal Univ, Coll Phys & Elect, Changsha 410081, Hunan, Peoples R China
[3] Cent South Univ, Sch Automat, Changsha 410083, Hunan, Peoples R China
[4] Univ Rwanda, Coll Sci & Technol, Kigali 3286, Rwanda
基金
中国国家自然科学基金;
关键词
Intrusion detection system; Gaussian mixture model; Greedy algorithm; Fuzzy rough set; Information gain ratio; Pattern learning; SUPPORT VECTOR MACHINE; DETECTION SYSTEM; TRANSITIVE CLOSURE; GENETIC-ALGORITHM; REDUCTION; OPTIMIZATION; HYPERGRAPH; PARAMETER; DENSITY;
D O I
10.1016/j.eswa.2019.112845
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this paper, an adaptive network intrusion detection method using fuzzy rough set-based feature selection and GA-GOGMM-based pattern learning is presented. Based on the fuzzy rough set theory, the optimal attribute subset of network connection records is achieved by the information gain ratio criterion in advance. A greedy algorithm-based global optimal Gaussian mixture model (GMM) clustering method, termed GA-GOGMM, is introduced, to extract the intrinsic structure of network instances to achieve highly-discernable and stable normal and intrusion pattern libraries for the subsequent network intrusion detection (NID). GA-GOGMM-based pattern learning can achieve the optimal GMM of network traffic instances for the pattern clustering while avoiding the negative effect of the empirical initialization of clustering numbers and random initialization of clustering centers with a low computational complexity. An adaptive model updating mechanism is further introduced for the online updating of normal and intrusion pattern libraries to ensure the adaptability of the NID model. Extensive validation and comparative experiments, conducted on a benchmark dataset NSL-KDD and a self-built Nidsbench-based network simulation platform, show that the proposed ANID approach leads to a significant improvement in detection accuracies with low false alarms and missing reports on both known and unknown attacks. It can effectively adapt to the dynamic changing network environments with high detection accuracy and low false alarm rate as well as low missing reporting rate, which has significant application prospects. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Adaptive network intrusion detection based on fuzzy rough set-based attribute reduction and GMM-LDA-based optimal cluster feature learning
    Liu J.-P.
    Zhang W.-X.
    Tang Z.-H.
    He J.-Z.
    Xu P.-F.
    [J]. Kongzhi yu Juece/Control and Decision, 2019, 34 (02): : 243 - 251
  • [2] Intuitionistic Fuzzy Rough Set-Based Granular Structures and Attribute Subset Selection
    Tan, Anhui
    Wu, Wei-Zhi
    Qian, Yuhua
    Liang, Jiye
    Chen, Jinkun
    Li, Jinjin
    [J]. IEEE TRANSACTIONS ON FUZZY SYSTEMS, 2019, 27 (03) : 527 - 539
  • [3] A Framework on Rough Set-Based Partitioning Attribute Selection
    Herawan, Tutut
    Deris, Mustafa Mat
    [J]. EMERGING INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS: WITH ASPECTS OF ARTIFICIAL INTELLIGENCE, 2009, 5755 : 91 - 100
  • [4] Intelligent temporal classification and fuzzy rough set-based feature selection algorithm for intrusion detection system in WSNs
    Selvakumar, K.
    Karuppiah, Marimuthu
    SaiRamesh, L.
    Islam, S. K. Hafizul
    Hassan, Mohammad Mehedi
    Fortino, Giancarlo
    Choo, Kim-Kwang Raymond
    [J]. INFORMATION SCIENCES, 2019, 497 : 77 - 90
  • [5] Fuzzy rough set-based attribute reduction using distance measures
    Wang, Changzhong
    Huang, Yang
    Shao, Mingwen
    Fan, Xiaodong
    [J]. KNOWLEDGE-BASED SYSTEMS, 2019, 164 : 205 - 212
  • [6] A rough set-based fuzzy clustering
    Zhao, YQ
    Zhou, XZ
    Tang, GZ
    [J]. INFORMATION RETRIEVAL TECHNOLOGY, PROCEEDINGS, 2005, 3689 : 401 - 409
  • [7] Performance Analysis Of Fuzzy Rough Set-Based And Correlation-Based Attribute Selection Methods On Detection Of Chronic Kidney Disease With Various Classifiers
    Basarslan, Muhammet Sinan
    Kayaalp, Fatih
    [J]. 2019 SCIENTIFIC MEETING ON ELECTRICAL-ELECTRONICS & BIOMEDICAL ENGINEERING AND COMPUTER SCIENCE (EBBT), 2019,
  • [8] Rough fuzzy set-based image compression
    Petrosino, Alfredo
    Ferone, Alessio
    [J]. FUZZY SETS AND SYSTEMS, 2009, 160 (10) : 1485 - 1506
  • [9] A novel approach of rough set-based attribute reduction using fuzzy discernibility matrix
    Yang, Ming
    Chen, Songcan
    Yang, Xubing
    [J]. FOURTH INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY, VOL 3, PROCEEDINGS, 2007, : 96 - 101
  • [10] An Intuitionistic Fuzzy-Rough Set-Based Classification for Anomaly Detection
    Mazarbhuiya, Fokrul Alom
    Shenify, Mohamed
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (09):