Hybrid intrusion detection with weighted signature generation over anomalous Internet episodes

被引:81
|
作者
Hwang, Kai [1 ]
Cai, Min [1 ]
Chen, Ying [1 ]
Qin, Min [1 ]
机构
[1] Univ So Calif, USC Viterbi Sch Engn, Internet & Grid Comp Lab, Los Angeles, CA 90089 USA
基金
美国国家科学基金会;
关键词
network security; intrusion detection systems; anomaly detection; signature generation; SNORT and Bro systems; false alarms; Internet episodes; traffic data mining;
D O I
10.1109/TDSC.2007.9
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This paper reports the design principles and evaluation results of a new experimental hybrid intrusion detection system (HIDS). This hybrid system combines the advantages of low false-positive rate of signature-based intrusion detection system (IDS) and the ability of anomaly detection system ( ADS) to detect novel unknown attacks. By mining anomalous traffic episodes from Internet connections, we build an ADS that detects anomalies beyond the capabilities of signature-based SNORT or Bro systems. A weighted signature generation scheme is developed to integrate ADS with SNORT by extracting signatures from anomalies detected. HIDS extracts signatures from the output of ADS and adds them into the SNORT signature database for fast and accurate intrusion detection. By testing our HIDS scheme over real-life Internet trace data mixed with 10 days of Massachusetts Institute of Technology/ Lincoln Laboratory (MIT/LL) attack data set, our experimental results show a 60 percent detection rate of the HIDS, compared with 30 percent and 22 percent in using the SNORT and Bro systems, respectively. This sharp increase in detection rate is obtained with less than 3 percent false alarms. The signatures generated by ADS upgrade the SNORT performance by 33 percent. The HIDS approach proves the vitality of detecting intrusions and anomalies, simultaneously, by automated data mining and signature generation over Internet connection episodes.
引用
收藏
页码:41 / 55
页数:15
相关论文
共 50 条
  • [31] Lightweight Intrusion Detection Model of the Internet of Things with Hybrid Cloud-Fog Computing
    Zhao, Guosheng
    Wang, Yang
    Wang, Jian
    SECURITY AND COMMUNICATION NETWORKS, 2023, 2023
  • [32] Intrusion detection in internet of things using differential privacy: A hybrid machine learning approach
    Manderna, Ankit
    Dohare, Upasana
    Kumar, Sushil
    Ram, Balak
    Ad Hoc Networks, 2025, 174
  • [33] A Hybrid Few-Shot Learning Based Intrusion Detection Method for Internet of Vehicles
    Zhao, Yixuan
    Cui, Jianming
    Liu, Ming
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT II, 2024, 14488 : 207 - 220
  • [34] Adaptive hybrid intrusion detection system for crowd sourced multimedia internet of things systems
    Venkatraman, S.
    Surendiran, B.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (5-6) : 3993 - 4010
  • [35] HDL-IDS: A Hybrid Deep Learning Architecture for Intrusion Detection in the Internet of Vehicles
    Ullah, Safi
    Khan, Muazzam A.
    Ahmad, Jawad
    Jamal, Sajjad Shaukat
    Huma, Zil E.
    Hassan, Muhammad Tahir
    Pitropakis, Nikolaos
    Arshad
    Buchanan, William J.
    SENSORS, 2022, 22 (04)
  • [36] Adaptive hybrid intrusion detection system for crowd sourced multimedia internet of things systems
    S. Venkatraman
    B. Surendiran
    Multimedia Tools and Applications, 2020, 79 : 3993 - 4010
  • [37] Dynamic distributed generative adversarial network for intrusion detection system over internet of things
    Balaji, S.
    Narayanan, S. Sankara
    WIRELESS NETWORKS, 2023, 29 (05) : 1949 - 1967
  • [38] Dynamic distributed generative adversarial network for intrusion detection system over internet of things
    S. Balaji
    S. Sankara Narayanan
    Wireless Networks, 2023, 29 : 1949 - 1967
  • [39] INTERNET ANOMALY DETECTION WITH WEIGHTED FUZZY MATCHING OVER FREQUENT EPISODE RULES
    Chen, Da-Peng
    Zhang, Xiao-Song
    2008 INTERNATIONAL CONFERENCE ON APPERCEIVING COMPUTING AND INTELLIGENCE ANALYSIS (ICACIA 2008), 2008, : 299 - 302
  • [40] Weighted Feature detection Mechanism for Internet of Vehicles over Heterogeneous Vehicular Network
    Alshehri, Hamdan A.
    2023 11TH INTERNATIONAL CONFERENCE ON SMART GRID, ICSMARTGRID, 2023,