A Cooperative and Hybrid Network Intrusion Detection Framework in Cloud Computing Based on Snort and Optimized Back Propagation Neural Network

被引:27
|
作者
Chiba, Z. [1 ]
Abghour, N. [1 ]
Moussaid, K. [1 ]
El Omri, A. [1 ]
Rida, M. [1 ]
机构
[1] Hassan II Univ Casablanca, Team Modeling & Optimizat Mobile Serv, Fac Sci, Casablanca 20100, Morocco
关键词
Cloud computing; Network intrusion detection; Back-propagation neural network; Snort; Optimization algorithm;
D O I
10.1016/j.procs.2016.04.249
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing provides a framework for supporting end users easily attaching powerful services and applications through Internet. To give secure and reliable services in cloud computing environment is an important issue. Providing security requires more than user authentication with passwords or digital certificates and confidentiality in data transmission, because it is vulnerable and prone to network intrusions that affect confidentiality, availability and integrity of Cloud resources and offered services. To detect DoS attack and other network level malicious activities in Cloud, use of only traditional firewall is not an efficient solution. In this paper, we propose a cooperative and hybrid network intrusion detection system (CH-NIDS) to detect network attacks in the Cloud environment by monitoring network traffic, while maintaining performance and service quality. In our NIDS framework, we use Snort as a signature based detection to detect known attacks, while for detecting network anomaly, we use Back-Propagation Neural network (BPN). By applying snort prior to the BPN classifier, BPN has to detect only unknown attacks. So, detection time is reduced. To solve the problem of slow convergence of BPN and being easy to fall into local optimum, we propose to optimize the parameters of it by using an optimization algorithm in order to ensure high detection rate, high accuracy, low false positives and low false negatives with affordable computational cost. In addition, in this framework, the IDSs operate in cooperative way to oppose the DoS and DDoS attacks by sharing alerts stored in central log. In this way, unknown attacks that were detected by any IDS can easily be detected by others IDSs. This also helps to reduce computational cost for detecting intrusions at others IDS, and improve detection rate in overall the Cloud environment. (C) 2016 The Authors. Published by Elsevier B.V.
引用
收藏
页码:1200 / 1206
页数:7
相关论文
共 50 条
  • [1] Bayesian Classifier and Snort based Network Intrusion Detection System in Cloud Computing
    Modi, Chirag N.
    Patel, Dhiren R.
    Patel, Avi
    Muttukrishnan, Rajarajan
    2012 THIRD INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION & NETWORKING TECHNOLOGIES (ICCCNT), 2012,
  • [2] HYBRID METAHEURISTIC ALGORITHM TUNED BACK PROPAGATION NEURAL NETWORK FOR INTRUSION DETECTION IN CLOUD ENVIRONMENT
    Thirumalairaj, Ayyappan
    Jeyakarthic, Mohan
    IIOAB JOURNAL, 2020, 11 (02) : 47 - 54
  • [3] Network Intrusion Detection Framework Based on Whale Swarm Algorithm and Artificial Neural Network in Cloud Computing
    Fahad, Ahmed Mohammed
    Ahmed, Abdulghani Ali
    Kahar, Mohd Nizam Mohmad
    INTELLIGENT COMPUTING & OPTIMIZATION, 2019, 866 : 56 - 65
  • [4] Network Intrusion Detection Based on Hybrid Neural Network
    He, Guofeng
    Lu, Qing
    Yin, Guangqiang
    Xiong, Hu
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2022), PT II, 2022, 13472 : 644 - 655
  • [5] RETRACTED: Intrusion detection in cloud environment using hybrid genetic algorithm and back propagation neural network (Retracted Article)
    Manimurugan, S.
    Manimegalai, P.
    Valsalan, Prajoona
    Krishnadas, J.
    Narmatha, C.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2022, 35 (16)
  • [6] An Optimized and Hybrid Framework for Image Processing Based Network Intrusion Detection System
    Siddiqi, Murtaza Ahmed
    Pak, Wooguil
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 73 (02): : 3921 - 3949
  • [7] Intrusion Detection for Network Based on Elite Clone Artificial Bee Colony and Back Propagation Neural Network
    Qi, Guohong
    Zhou, Jie
    Jia, Wenxian
    Liu, Menghan
    Zhang, Shengnan
    Xu, Mengying
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [8] A framework for Network Intrusion Detection in Cloud
    Prwez, Md Tarique
    Chatterjee, Kakali
    2016 IEEE 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (IACC), 2016, : 512 - 516
  • [9] HybGBS: A hybrid neural network and grey wolf optimizer for intrusion detection in a cloud computing environment
    Sumathi, S.
    Rajesh, R.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (24):
  • [10] A Back Propagation Neural Network for Evaluating Collaborative Performance in Cloud Computing
    Song, Biao
    Hassan, Mohammad Mehedi
    Tian, Yuan
    Huh, Eui-Nam
    GRID AND DISTRIBUTED COMPUTING, 2009, 63 : 57 - 64