复杂计算机网络中基于异常的入侵检测混合模型

D. Protić, M. Stankovic
{"title":"复杂计算机网络中基于异常的入侵检测混合模型","authors":"D. Protić, M. Stankovic","doi":"10.1109/ACIT50332.2020.9299965","DOIUrl":null,"url":null,"abstract":"Anomaly-based intrusion detection classifiers detect the notion of normality and classify both intrusion and/or misuse as either 'normal' or 'anomaly'. In complex computer networks, the number of the training records is often large which makes the evaluation of the classifiers computationally expensive. In this paper we present a feature selection and instances normalization algorithm that reduces the dimensionality of the dataset size, decrease processing time and increase accuracy of two classifier models, namely weighted k-Nearest Neighbor (wk-NN) and Feedforward Neural Network (FNN). The experiments are conducted on three daily records of the real computer network traffic data derived from the Kyoto 2006+ dataset. The results show high accuracy of both wk-NN and FNN classifiers but variations in mutual decisions on detected anomalies. Variations are determined with the novel hybrid model by performing logical exclusive or operation to the predicted outcomes. Improvement in the anomaly detection ranges from 0.67% to 8.08%.","PeriodicalId":193891,"journal":{"name":"2020 21st International Arab Conference on Information Technology (ACIT)","volume":"86 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"A Hybrid Model for Anomaly-Based Intrusion Detection in Complex Computer Networks\",\"authors\":\"D. Protić, M. Stankovic\",\"doi\":\"10.1109/ACIT50332.2020.9299965\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Anomaly-based intrusion detection classifiers detect the notion of normality and classify both intrusion and/or misuse as either 'normal' or 'anomaly'. In complex computer networks, the number of the training records is often large which makes the evaluation of the classifiers computationally expensive. In this paper we present a feature selection and instances normalization algorithm that reduces the dimensionality of the dataset size, decrease processing time and increase accuracy of two classifier models, namely weighted k-Nearest Neighbor (wk-NN) and Feedforward Neural Network (FNN). The experiments are conducted on three daily records of the real computer network traffic data derived from the Kyoto 2006+ dataset. The results show high accuracy of both wk-NN and FNN classifiers but variations in mutual decisions on detected anomalies. Variations are determined with the novel hybrid model by performing logical exclusive or operation to the predicted outcomes. Improvement in the anomaly detection ranges from 0.67% to 8.08%.\",\"PeriodicalId\":193891,\"journal\":{\"name\":\"2020 21st International Arab Conference on Information Technology (ACIT)\",\"volume\":\"86 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-11-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 21st International Arab Conference on Information Technology (ACIT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ACIT50332.2020.9299965\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 21st International Arab Conference on Information Technology (ACIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ACIT50332.2020.9299965","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

基于异常的入侵检测分类器检测正常的概念,并将入侵和/或滥用分类为“正常”或“异常”。在复杂的计算机网络中,训练记录的数量往往很大,这使得分类器的评估计算成本很高。在本文中,我们提出了一种特征选择和实例归一化算法,该算法降低了数据集大小的维数,减少了处理时间,提高了两种分类器模型的精度,即加权k-近邻(wk-NN)和前馈神经网络(FNN)。实验采用京都2006+数据集的3个真实计算机网络流量日记录进行。结果表明,wk-NN和FNN分类器的准确率都很高,但在对检测到的异常的相互决策上存在差异。通过对预测结果执行逻辑排他或运算,利用新型混合模型确定变量。异常检测的改进幅度为0.67% ~ 8.08%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
A Hybrid Model for Anomaly-Based Intrusion Detection in Complex Computer Networks
Anomaly-based intrusion detection classifiers detect the notion of normality and classify both intrusion and/or misuse as either 'normal' or 'anomaly'. In complex computer networks, the number of the training records is often large which makes the evaluation of the classifiers computationally expensive. In this paper we present a feature selection and instances normalization algorithm that reduces the dimensionality of the dataset size, decrease processing time and increase accuracy of two classifier models, namely weighted k-Nearest Neighbor (wk-NN) and Feedforward Neural Network (FNN). The experiments are conducted on three daily records of the real computer network traffic data derived from the Kyoto 2006+ dataset. The results show high accuracy of both wk-NN and FNN classifiers but variations in mutual decisions on detected anomalies. Variations are determined with the novel hybrid model by performing logical exclusive or operation to the predicted outcomes. Improvement in the anomaly detection ranges from 0.67% to 8.08%.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Wireless Sensor Network MAC Energy - efficiency Protocols: A Survey Keystroke Identifier Using Fuzzy Logic to Increase Password Security A seq2seq Neural Network based Conversational Agent for Gulf Arabic Dialect Machine Learning and Soft Robotics Studying and Analyzing the Fog-based Internet of Robotic Things
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1