GARUDA: Gaussian dissimilarity measure for feature representation and anomaly detection in Internet of things

被引:55
作者
Aljawarneh, Shadi A. [1 ]
Vangipuram, Radhakrishna [2 ]
机构
[1] Jordan Univ Sci & Technol, Irbid, Jordan
[2] VNR Vignana Jyothi Inst Engn & Technol, Ctr Excellence Networks & Secur, Dept Informat Technol, Hyderabad, India
关键词
Anomaly detection; Feature representation; Intrusion; Dimensionality; Clustering; Distance measure; INTRUSION-DETECTION; SIMILARITY MEASURE; FEATURE-SELECTION; ALGORITHM; NETWORKS; TRENDS;
D O I
10.1007/s11227-018-2397-3
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The objective of any anomaly detection system is to efficiently detect several types of malicious traffic patterns that cannot be detected by conventional firewall systems. Designing an efficient intrusion detection system has three primary challenges that include addressing high dimensionality problem, choice of learning algorithm, and distance or similarity measure used to find the similarity value between any two traffic patterns or input observations. Feature representation and dimensionality reduction have been studied and addressed widely in the literature and have also been applied for the design of intrusion detection systems (IDS). The choice of classifiers is also studied and applied widely in the design of IDS. However, at the heart of IDS lies the choice of distance measure that is required for an IDS to judge an incoming observation as normal or abnormal. This challenge has been understudied and relatively less addressed in the research literature both from academia and from industry. This research aims at introducing a novel distance measure that can be used to perform feature clustering and feature representation for efficient intrusion detection. Recent studies such as CANN proposed feature reduction techniques for improving detection and accuracy rates of IDS that used Euclidean distance. However, accuracies of attack classes such as U2R and R2L are not significantly promising. Our approach GARUDA is based on clustering feature patterns incrementally and then representing features in different transformation space through using a novel fuzzy Gaussian dissimilarity measure. Experiments are conducted on both KDD and NSL-KDD datasets. The accuracy and detection rates of proposed approach are compared for classifiers such as kNN, J48, naive Bayes, along with CANN and CLAPP approaches. Experiment results proved that proposed approach resulted in the improved accuracy and detection rates for U2R and R2L attack classes when compared to other approaches.
引用
收藏
页码:4376 / 4413
页数:38
相关论文
共 50 条
  • [21] Federated deep learning for anomaly detection in the internet of things
    Wang, Xiaofeng
    Wang, Yonghong
    Javaheri, Zahra
    Almutairi, Laila
    Moghadamnejad, Navid
    Younes, Osama S.
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 108
  • [22] A Survey on Explainable Anomaly Detection for Industrial Internet of Things
    Huang, Zijie
    Wu, Yulei
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,
  • [23] Metaheuristic feature selection with deep learning enabled cascaded recurrent neural network for anomaly detection in Industrial Internet of Things environment
    Chander, Nenavath
    Kumar, Mummadi Upendra
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2023, 26 (03): : 1801 - 1819
  • [24] Metaheuristic feature selection with deep learning enabled cascaded recurrent neural network for anomaly detection in Industrial Internet of Things environment
    Nenavath Chander
    Mummadi Upendra Kumar
    Cluster Computing, 2023, 26 : 1801 - 1819
  • [25] A Novel Method for Anomaly Detection in the Internet of Things using Whale Optimization Algorithm
    Zhu, Zhihui
    Zhu, Meifang
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (05) : 765 - 773
  • [26] Review of filtering based feature selection for Botnet detection in the Internet of Things
    Saied, Mohamed
    Guirguis, Shawkat
    Madbouly, Magda
    ARTIFICIAL INTELLIGENCE REVIEW, 2025, 58 (04)
  • [27] Multivariate time series anomaly detection with adversarial transformer architecture in the Internet of Things
    Zeng, Fanyu
    Chen, Mengdong
    Qian, Cheng
    Wang, Yanyang
    Zhou, Yijun
    Tang, Wenzhong
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 144 : 244 - 255
  • [28] NADS-RA: Network Anomaly Detection Scheme Based on Feature Representation and Data Augmentation
    Liu, Xu
    Di, Xiaoqiang
    Ding, Qiang
    Liu, Weiyou
    Qi, Hui
    Li, Jinqing
    Yang, Huamin
    IEEE ACCESS, 2020, 8 : 214781 - 214800
  • [29] Anomaly Detection Framework in Fog-to-Things Communication for Industrial Internet of Things
    Alatawi, Tahani
    Aljuhani, Ahamed
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 73 (01): : 1067 - 1086
  • [30] READ-IoT: Reliable Event and Anomaly Detection Framework for the Internet of Things
    Yahyaoui, Aymen
    Abdellatif, Takoua
    Yangui, Sami
    Attia, Rabah
    IEEE ACCESS, 2021, 9 : 24168 - 24186