PCA filtering and probabilistic SOM for network intrusion detection

被引:118
|
作者
De la Hoz, Eduardo [1 ]
De La Hoz, Emiro [1 ]
Ortiz, Andres [2 ]
Ortega, Julio [3 ]
Prieto, Beatriz [3 ]
机构
[1] Univ Costa, Programa Ingn Sistemas, Barranquilla, Colombia
[2] Univ Malaga, Dept Commun Engn, E-29071 Malaga, Spain
[3] Univ Granada, CITIC, Comp Architecture & Technol Dept, E-18071 Granada, Spain
关键词
Probabilistic SOM; Bayesian SOM; IDS; Self-organizing maps; PCA filtering; FEATURE-SELECTION;
D O I
10.1016/j.neucom.2014.09.083
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The growth of the Internet and, consequently, the number of interconnected computers, has exposed significant amounts of information to intruders and attackers. Firewalls aim to detect violations according to a predefined rule-set and usually block potentially dangerous incoming traffic. However, with the evolution of attack techniques, it is more difficult to distinguish anomalies from normal traffic. Different detection approaches have been proposed, including the use of machine learning techniques based on neural models such as Self-Organizing Maps (SOMs). In this paper, we present a classification approach that hybridizes statistical techniques and SOM for network anomaly detection. Thus, while Principal Component Analysis (PCA) and Fisher Discriminant Ratio (FDR) have been considered for feature selection and noise removal, Probabilistic Self-Organizing Maps (PSOM) aim to model the feature space and enable distinguishing between normal and anomalous connections. The detection capabilities of the proposed system can be modified without retraining the map, but only by modifying the units activation probabilities. This deals with fast implementations of Intrusion Detection Systems (IDS) necessary to cope with current link bandwidths. (C) 2015 Elsevier B.V. All rights reserved.
引用
收藏
页码:71 / 81
页数:11
相关论文
共 50 条
  • [41] SPIDER: A shallow PCA based network intrusion detection system with enhanced recurrent neural networks
    Udas, Pritom Biswas
    Karim, Md. Ebtidaul
    Roy, Kowshik Sankar
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 10246 - 10272
  • [42] Fault detection method for nonlinear systems based on probabilistic neural network filtering
    Liu, J
    Scherpen, JMA
    INTERNATIONAL JOURNAL OF SYSTEMS SCIENCE, 2002, 33 (13) : 1039 - 1050
  • [43] ProIDS: Probabilistic Data Structures based Intrusion Detection System for Network Traffic Monitoring
    Gupta, Divya
    Garg, Sahil
    Singh, Amritpal
    Batra, Shalini
    Kumar, Neeraj
    Obaidat, M. S.
    GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [44] Application of Clustering Algorithm in Intrusion Detection Based on PCA
    Li, Han
    2015 International Conference on Software Engineering and Information System (SEIS 2015), 2015, : 239 - 244
  • [45] Ada-Boosted Locally Enhanced Probabilistic Neural Network for IoT Intrusion Detection
    Jan, Tony
    COMPLEX, INTELLIGENT, AND SOFTWARE INTENSIVE SYSTEMS, 2019, 772 : 583 - 589
  • [46] An optimized intrusion detection system using PCA and BNN
    Dong Seong Kim
    Ha-Nam Nguyen
    Thandar Thein
    Jong Son Park
    APSITT 2005: 6TH ASIA-PACIFIC SYMPOSIUM ON INFORMATION AND TELECOMMUNICATION TECHNOLOGIES, PROCEEDINGS, 2005, : 356 - 359
  • [47] Leveraging a Probabilistic PCA Model to Understand the Multivariate Statistical Network Monitoring Framework for Network Security Anomaly Detection
    Perez-Bueno, Fernando
    Garcia, Luz
    Macia-Fernandez, Gabriel
    Molina, Rafael
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1217 - 1229
  • [48] Hybrid SOM–PCA method for modeling bearing faults detection and diagnosis
    Mohamed Lamine Fadda
    Abdelkrim Moussaoui
    Journal of the Brazilian Society of Mechanical Sciences and Engineering, 2018, 40
  • [49] Intrusion detection model in network systems, making feature selection with FDR and classification-training stages with SOM
    De la Hoz, Emiro
    Miguel De la Hoz, Eduardo
    Ortiz, Andres
    Ortega, Julio
    INGE CUC, 2012, 8 (01) : 85 - 116
  • [50] Wireless Intrusion Detection: Not as easy as traditional network intrusion detection
    Tao, Zhiqi
    Ruighaver, A. B.
    TENCON 2005 - 2005 IEEE REGION 10 CONFERENCE, VOLS 1-5, 2006, : 2513 - +