A Cooperative and Hybrid Network Intrusion Detection Framework in Cloud Computing Based on Snort and Optimized Back Propagation Neural Network

被引:27
|
作者
Chiba, Z. [1 ]
Abghour, N. [1 ]
Moussaid, K. [1 ]
El Omri, A. [1 ]
Rida, M. [1 ]
机构
[1] Hassan II Univ Casablanca, Team Modeling & Optimizat Mobile Serv, Fac Sci, Casablanca 20100, Morocco
关键词
Cloud computing; Network intrusion detection; Back-propagation neural network; Snort; Optimization algorithm;
D O I
10.1016/j.procs.2016.04.249
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing provides a framework for supporting end users easily attaching powerful services and applications through Internet. To give secure and reliable services in cloud computing environment is an important issue. Providing security requires more than user authentication with passwords or digital certificates and confidentiality in data transmission, because it is vulnerable and prone to network intrusions that affect confidentiality, availability and integrity of Cloud resources and offered services. To detect DoS attack and other network level malicious activities in Cloud, use of only traditional firewall is not an efficient solution. In this paper, we propose a cooperative and hybrid network intrusion detection system (CH-NIDS) to detect network attacks in the Cloud environment by monitoring network traffic, while maintaining performance and service quality. In our NIDS framework, we use Snort as a signature based detection to detect known attacks, while for detecting network anomaly, we use Back-Propagation Neural network (BPN). By applying snort prior to the BPN classifier, BPN has to detect only unknown attacks. So, detection time is reduced. To solve the problem of slow convergence of BPN and being easy to fall into local optimum, we propose to optimize the parameters of it by using an optimization algorithm in order to ensure high detection rate, high accuracy, low false positives and low false negatives with affordable computational cost. In addition, in this framework, the IDSs operate in cooperative way to oppose the DoS and DDoS attacks by sharing alerts stored in central log. In this way, unknown attacks that were detected by any IDS can easily be detected by others IDSs. This also helps to reduce computational cost for detecting intrusions at others IDS, and improve detection rate in overall the Cloud environment. (C) 2016 The Authors. Published by Elsevier B.V.
引用
收藏
页码:1200 / 1206
页数:7
相关论文
共 50 条
  • [41] cl-CIDPS: A Cloud Computing Based Cooperative Intrusion Detection and Prevention System Framework
    Al-Mousa, Zahraa
    Nasir, Qassim
    FUTURE NETWORK SYSTEMS AND SECURITY, FNSS 2015, 2015, 523 : 181 - 194
  • [42] An Enhanced Approach for Intrusion Detection in Virtual Network of Cloud Computing
    Kadam, Deeksha
    Patil, Rajendra
    Modi, Chirag
    2018 10TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2018, : 80 - 87
  • [43] A Cloud Based Network Intrusion Detection System
    You, Li
    Wang, Zhanyong
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2022, 29 (03): : 987 - 992
  • [44] Privacy Preserving Back-Propagation Neural Network Learning Made Practical with Cloud Computing
    Yuan, Jiawei
    Yu, Shucheng
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (01) : 212 - 221
  • [45] A Hybrid Intrusion Detection Method Based on Convolutional Neural Network and AdaBoost
    Wu, Zhijun
    Li, Yuqi
    Yue, Meng
    CHINA COMMUNICATIONS, 2024, 21 (11) : 180 - 189
  • [46] A Hybrid Intrusion Detection Method Based on Convolutional Neural Network and AdaBoost
    Wu Zhijun
    Li Yuqi
    Yue Meng
    China Communications, 2024, 21 (11) : 180 - 189
  • [47] Double fuzzy clustering-driven context neural network for intrusion detection in cloud computing
    Velavan, S. Anu
    Sureshkumar, C.
    WIRELESS NETWORKS, 2025, 31 (03) : 2513 - 2524
  • [48] A Novel Hybrid-Network Intrusion Detection System (H-NIDS) in Cloud Computing
    Modi, Chirag N.
    Patel, Dhiren
    2013 IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE IN CYBER SECURITY (CICS), 2013, : 23 - 30
  • [49] A HYBRID FRAMEWORK BASED ON NEURAL NETWORK MLP AND K-MEANS CLUSTERING FOR INTRUSION DETECTION SYSTEM
    Lisehroodi, Mazyar Mohammadi
    Muda, Zaiton
    Yassin, Warusia
    COMPUTING & INFORMATICS, 4TH INTERNATIONAL CONFERENCE, 2013, 2013, : 305 - +
  • [50] Network Intrusion Detection Based on a General Regression Neural Network Optimized by an Improved Artificial Immune Algorithm
    Wu, Jianfa
    Peng, Dahao
    Li, Zhuping
    Zhao, Li
    Ling, Huanzhang
    PLOS ONE, 2015, 10 (03):