Web-based monitoring approach for network-based intrusion detection and prevention

被引:0
|
作者
Naruemon Wattanapongsakorn
Chalermpol Charnsripinyo
机构
[1] King Mongkut’s University of Technology Thonburi,Department of Computer Engineering
[2] National Electronics and Computer Technology Center,undefined
来源
关键词
Web-based IDPS; Real-time detection; Intrusion detection system; Network security system; Machine learning technique;
D O I
暂无
中图分类号
学科分类号
摘要
There were many reports about incidents of network attacks and security treats. Damages caused by network attacks and malwares can be extremely expensive or unaffordable. In this paper, we present a web-based management system for network-based intrusion detection and prevention. Users can get access from any mobile devices to see current network status, if there is an incident of network attack in the network environment. Our intrusion detection and prevention systems (IDPS) can be applied with different well-known detection algorithms which are C4.5 Decision Tree, Random Forest, Ripple Rule, Bayesian Network, Back-Propagation Neural Network. These algorithms can give very high detection accuracy for known attacks, where the attack type was previously trained/ learnt by the system. However, when new or unfamiliar/unknown attacks are encountered, the algorithms do not perform well. So, we develop a new detection technique based on Fuzzy Genetic Algorithm (Fuzzy GA) to handle the problem. Our IDPS can work in real-time, where detection results will be reported within 2–3 s. The IDPS will automatically protect the network by dropping the malicious network packets or block the network ports that are abused by the attackers. In addition, the proposed IDPS can detect network attacks at different locations inside the network by using several client machines to capture data packets and then send information to the server in order to classify types of network attacks. The proposed IDPS also allows system administrator to update existing detection rule sets or learn new training datasets with a friendly graphic user interface. In our experiments, we can correctly detect and prevent network attacks with high accuracy, more than 97 %.
引用
收藏
页码:6391 / 6411
页数:20
相关论文
共 50 条
  • [31] An Intrusion Detection System Using the Artificial Neural Network-based Approach and Firefly Algorithm
    Rajabi, Samira
    Asgari, Samane
    Jamali, Shahram
    Fotohi, Reza
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2024, 137 (04) : 2409 - 2440
  • [32] Cellular Neural Network-Based Methods for Distributed Network Intrusion Detection
    Xie, Kang
    Yang, Yixian
    Xin, Yang
    Xia, Guangsheng
    [J]. MATHEMATICAL PROBLEMS IN ENGINEERING, 2015, 2015
  • [33] A Quantum Generative Adversarial Network-based Intrusion Detection System
    Rahman, Md Abdur
    Shahriar, Hossain
    Clincy, Victor
    Hossain, Md Faruque
    Rahman, Muhammad
    [J]. 2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 1810 - 1815
  • [34] A Neural Network-Based Learning Algorithm for Intrusion Detection Systems
    Hassan I. Ahmed
    Nawal A. Elfeshawy
    S. F. Elzoghdy
    Hala S. El-sayed
    Osama S. Faragallah
    [J]. Wireless Personal Communications, 2017, 97 : 3097 - 3112
  • [35] Network-based anomaly intrusion detection system using SOMs
    Depren, MÖ
    Topallar, M
    Anarim, E
    Ciliz, K
    [J]. PROCEEDINGS OF THE IEEE 12TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE, 2004, : 76 - 79
  • [36] A Neural Network-Based Learning Algorithm for Intrusion Detection Systems
    Ahmed, Hassan I.
    Elfeshawy, Nawal A.
    Elzoghdy, S. F.
    El-sayed, Hala S.
    Faragallah, Osama S.
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2017, 97 (02) : 3097 - 3112
  • [37] Modeling and performance analysis of network-based intrusion detection cluster
    Jiang, YX
    Lin, C
    Shan, ZG
    Chen, Z
    [J]. PARALLEL AND DISTRIBUTED COMPUTING SYSTEMS, 2004, : 530 - 535
  • [38] HIDMN: A Host and Network-based Intrusion Detection for Mobile Networks
    Bijani, Shahriar
    Kazemitabar, Maryamosadat A.
    [J]. ICCEE 2008: PROCEEDINGS OF THE 2008 INTERNATIONAL CONFERENCE ON COMPUTER AND ELECTRICAL ENGINEERING, 2008, : 204 - 208
  • [39] Research Trends in Network-Based Intrusion Detection Systems: A Review
    Kumar, Satish
    Gupta, Sunanda
    Arora, Sakshi
    [J]. IEEE ACCESS, 2021, 9 : 157761 - 157779
  • [40] Design on Test Method of Network-based Intrusion Detection System
    Shen, Liang
    Yang, Yuanyuan
    Wang, Zhijia
    Zhang, Xiaoxiao
    Gu, Jian
    [J]. 2012 INTERNATIONAL CONFERENCE ON CONTROL ENGINEERING AND COMMUNICATION TECHNOLOGY (ICCECT 2012), 2012, : 661 - 664