Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection

被引:40
|
作者
Meng, Yuxin [1 ]
Kwok, Lam-For [1 ]
机构
[1] City Univ Hong Kong, Dept Comp Sci, Kowloon, Hong Kong, Peoples R China
关键词
Network Intrusion Detection; Intelligent False Alarm Reduction; Ensemble Selection;
D O I
10.1080/18756891.2013.802114
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level.
引用
收藏
页码:626 / 638
页数:13
相关论文
共 50 条
  • [1] Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
    Yuxin Meng
    Lam-For Kwok
    International Journal of Computational Intelligence Systems, 2013, 6 : 626 - 638
  • [2] Network specific false alarm reduction in intrusion detection system
    Hubballi, Neminath
    Biswas, Santosh
    Nandi, Sukumar
    SECURITY AND COMMUNICATION NETWORKS, 2011, 4 (11) : 1339 - 1349
  • [3] False Alarm Reduction in ICU Using Ensemble Classifier Approach
    Chandar, V. Ravindra Krishna
    Thangamani, M.
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 34 (01): : 165 - 181
  • [4] Adaptive SVDD-based Learning for False Alarm Reduction in Intrusion Detection
    Kenaza, Tayeb
    Labed, Abdenour
    Boulahia, Yacine
    Sebehi, Mohcen
    2015 12TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (ICETE), VOL 4, 2015, : 405 - 412
  • [5] Adaptive False Alarm Filter Using Machine Learning in Intrusion Detection
    Meng, Yuxin
    Kwok, Lam-for
    PRACTICAL APPLICATIONS OF INTELLIGENT SYSTEMS, 2011, 124 : 573 - 584
  • [6] Improving False Alarm Rate in Intrusion Detection Systems Using Hadoop
    Mukund, Y. R.
    Nayak, Sunil S.
    Chandrasekaran, K.
    2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 837 - 843
  • [7] EL-FAM: Power System Intrusion Detection with Ensemble Learning for False Alarm Mitigation
    Bhavsar, Ansh
    Agvan, Sezan
    Ramoliya, Fenil
    Obaidiat, Mohammad S.
    Gupta, Rajesh
    Tanwar, Sudeep
    Hsiao, Kuei-Fang
    2024 INTERNATIONAL CONFERENCE ON COMPUTER, INFORMATION AND TELECOMMUNICATION SYSTEMS, CITS 2024, 2024, : 133 - 137
  • [8] Intrusion Detection System using Bagging Ensemble Selection
    Sreenath, M.
    Udhayan, J.
    2015 IEEE INTERNATIONAL CONFERENCE ON ENGINEERING AND TECHNOLOGY (ICETECH), 2015, : 4 - 7
  • [9] Enhancing Intelligent Alarm Reduction for Distributed Intrusion Detection Systems via Edge Computing
    Meng, Weizhi
    Wang, Yu
    Li, Wenjuan
    Liu, Zhe
    Li, Jin
    Probst, Christian W.
    INFORMATION SECURITY AND PRIVACY, 2018, 10946 : 759 - 767
  • [10] Towards an Information-Theoretic Approach for Measuring Intelligent False Alarm Reduction in Intrusion Detection
    Meng, Yuxin
    Kwok, Lam-For
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 241 - 248