An intelligent intrusion detection system (IDS) for anomaly and misuse detection in computer networks

被引:273
|
作者
Depren, O [1 ]
Topallar, M [1 ]
Anarim, E [1 ]
Ciliz, MK [1 ]
机构
[1] Bogazici Univ, Dept Elect Engn & Elect, Informat & Commun Secur Lab, Istanbul, Turkey
关键词
intrusion detection; anomaly detection; misuse detection; SOM; decision trees; J.48; KDD Cup 99; hybrid intrusion detection;
D O I
10.1016/j.eswa.2005.05.002
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this paper, we propose a novel Intrusion Detection System (IDS) architecture utilizing both anomaly and misuse detection approaches. This hybrid Intrusion Detection System architecture consists of an anomaly detection module, a misuse detection module and a decision support system combining the results of these two detection modules. The proposed anomaly detection module uses a Self-Organizing Map (SOM) structure to model normal behavior. Deviation from the normal behavior is classified as an attack. The proposed misuse detection module uses J.48 decision tree algorithm to classify various types of attacks. The principle interest of this work is to benchmark the performance of the proposed hybrid IDS architecture by using KDD Cup 99 Data Set, the benchmark dataset used by IDS researchers. A rule-based Decision Support System (DSS) is also developed for interpreting the results of both anomaly and misuse detection modules. Simulation results of both anomaly and misuse detection modules based on the KDD 99 Data Set are given. It is observed that the proposed hybrid approach gives better performance over individual approaches. (c) 2005 Elsevier Ltd. All rights reserved.
引用
收藏
页码:713 / 722
页数:10
相关论文
共 50 条
  • [1] The multi-demeanor fusion based robust intrusion detection system for anomaly and misuse detection in computer networks
    Gupta, Akshay Rameshbhai
    Agrawal, Jitendra
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2021, 12 (01) : 303 - 319
  • [2] The multi-demeanor fusion based robust intrusion detection system for anomaly and misuse detection in computer networks
    Akshay Rameshbhai Gupta
    Jitendra Agrawal
    Journal of Ambient Intelligence and Humanized Computing, 2021, 12 : 303 - 319
  • [3] An intelligent lightweight intrusion detection system(IDS)
    Hu Zheng Bing
    Shirochin, V. P.
    Su Jun
    TENCON 2005 - 2005 IEEE REGION 10 CONFERENCE, VOLS 1-5, 2006, : 2202 - 2208
  • [4] An intelligent lightweight intrusion detection system(IDS)
    Hu, ZB
    Shirochin, VP
    Yang, YP
    Eurocon 2005: The International Conference on Computer as a Tool, Vol 1 and 2 , Proceedings, 2005, : 652 - 655
  • [5] Intrusion Detection System based on Anomaly and Misuse
    Zhou, YuPing
    Zheng, LiPing
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON MODELLING AND SIMULATION (ICMS2009), VOL 7, 2009, : 474 - 479
  • [6] Intrusion Detection System (IDS): Anomaly Detection using Outlier Detection Approach
    Jabez, J.
    Muthukumar, B.
    INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION AND CONVERGENCE (ICCC 2015), 2015, 48 : 338 - 346
  • [7] Computer Immunity Using An Intrusion Detection System (IDS)
    Konyeha, Susan
    Onibere, Emmanuel A.
    ADVANCES IN MATERIALS AND SYSTEMS TECHNOLOGIES IV, 2013, 824 : 200 - 205
  • [8] Passban IDS: An Intelligent Anomaly-Based Intrusion Detection System for IoT Edge Devices
    Eskandari, Mojtaba
    Janjua, Zaffar Haider
    Vecchio, Massimo
    Antonelli, Fabio
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (08): : 6882 - 6897
  • [9] Classification of Intrusion Detection System (IDS) Based on Computer Network
    Effendy, David Ahmad
    Kusrini, Kusrini
    Sudarmawan, Sudarmawan
    2017 2ND INTERNATIONAL CONFERENCES ON INFORMATION TECHNOLOGY, INFORMATION SYSTEMS AND ELECTRICAL ENGINEERING (ICITISEE): OPPORTUNITIES AND CHALLENGES ON BIG DATA FUTURE INNOVATION, 2017, : 90 - 94
  • [10] Intelligent Hybrid Anomaly Network Intrusion Detection System
    Eid, Heba F.
    Darwish, Ashraf
    Hassanien, Aboul Ella
    Kim, Tai-hoon
    COMMUNICATION AND NETWORKING, PT I, 2011, 265 : 209 - +