Unknown Attack Detection: Combining Relabeling and Hybrid Intrusion Detection

被引:3
|
作者
Shin, Gun-Yoon [1 ]
Kim, Dong-Wook [1 ]
Kim, Sang-Soo [2 ]
Han, Myung-Mook [3 ]
机构
[1] Gachon Univ, Dept Comp Engn, Sungnam Si 13120, South Korea
[2] Agcy Def Dev Songpa, Seoul 05661, South Korea
[3] Gachon Univ, Dept Software, Sungnam Si 13120, South Korea
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2021年 / 68卷 / 03期
基金
新加坡国家研究基金会;
关键词
Unknown attack; hybrid intrusion detection; fuzzy c-means; relabeling; CART; iForest; ANOMALY DETECTION; ALGORITHM;
D O I
10.32604/cmc.2021.017502
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detection of unknown attacks like a zero-day attack is a research field that has long been studied. Recently, advances in Machine Learning (ML) and Artificial Intelligence (AI) have led to the emergence of many kinds of attack-generation tools developed using these technologies to evade detection skillfully. Anomaly detection and misuse detection are the most commonly used techniques for detecting intrusion by unknown attacks. Although anomaly detection is adequate for detecting unknown attacks, its disadvantage is the possibility of high false alarms. Misuse detection has low false alarms; its limitation is that it can detect only known attacks. To overcome such limitations, many researchers have proposed a hybrid intrusion detection that integrates these two detection techniques. This method can overcome the limitations of conventional methods and works better in detecting unknown attacks. However, this method does not accurately classify attacks like similar to normal or known attacks. Therefore, we proposed a hybrid intrusion detection to detect unknown attacks similar to normal and known attacks. In anomaly detection, the model was designed to perform normal detection using Fuzzy c-means (FCM) and identify attacks hidden in normal predicted data using relabeling. In misuse detection, the model was designed to detect previously known attacks using Classification and Regression Trees (CART) and apply Isolation Forest (iForest) to classify unknown attacks hidden in known attacks. As an experiment result, the application of relabeling improved attack detection accuracy in anomaly detection by approximately 11% and enhanced the performance of unknown attack detection in misuse detection by approximately 10%.
引用
收藏
页码:3289 / 3303
页数:15
相关论文
共 50 条
  • [1] Improvement of the Classification Performance of an Intrusion Detection Model for Rare and Unknown Attack Traffic
    Han, Sangsoo
    Kim, Youngwon
    Lee, Soojin
    [J]. ELECTRONICS, 2021, 10 (18)
  • [2] Hybrid Intrusion Detection: Combining Decision Tree and Gaussian Mixture Model
    Bitaab, Marzieh
    Hashemi, Sattar
    [J]. 2017 14TH INTERNATIONAL ISC (IRANIAN SOCIETY OF CRYPTOLOGY) CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2017, : 8 - 12
  • [3] Preventing Unknown Malware Attack by using Intelligence intrusion Multi detection prevention Systems
    Kuppusamy, K.
    Murugan, S.
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2009, 9 (12): : 299 - 307
  • [4] Employing Attack Graphs for Intrusion Detection
    Capobianco, Frank
    George, Rahul
    Huang, Kaiming
    Jaeger, Trent
    Krishnamurthy, Srikanth
    Qian, Zhiyun
    Payer, Mathias
    Yu, Paul
    [J]. NSPW'19: PROCEEDINGS OF THE NEW SECURITY PARADIGMS WORKSHOP, 2019, : 16 - 30
  • [5] Combining Multiple Techniques for Intrusion Detection
    Katar, Chaker
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2006, 6 (2B): : 208 - 218
  • [6] A Lightweight Multi-Attack CAN Intrusion Detection System on Hybrid FPGAs
    Khandelwal, Shashwat
    Shreejith, Shanker
    [J]. 2022 32ND INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE LOGIC AND APPLICATIONS, FPL, 2022, : 425 - 429
  • [7] Intrusion Detection Combining Multiple Methods
    Dai Hong
    Li Haibo
    [J]. PROCEEDINGS OF THE 14TH YOUTH CONFERENCE ON COMMUNICATION, 2009, : 411 - +
  • [8] A MSPCA based Intrusion Detection Algorithm for Detection of DDoS Attack
    Chen, Zhaomin
    Yeo, Chai Kiat
    Francis, Bu Sung Lee
    Lau, Chiew Tong
    [J]. 2015 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2015,
  • [9] Probe Attack Detection Using an Improved Intrusion Detection System
    Almazyad, Abdulaziz
    Halman, Laila
    Alsaeed, Alaa
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (03): : 4769 - 4784
  • [10] Hybrid Intrusion Detection System
    Adhao, Rahul B.
    Mahefuj, Samadhan J.
    Pachghare, Vinod K.
    Khadse, Vijay M.
    [J]. INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING, 2021, 12 (05): : 573 - 579