Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection

被引:40
|
作者
Meng, Yuxin [1 ]
Kwok, Lam-For [1 ]
机构
[1] City Univ Hong Kong, Dept Comp Sci, Kowloon, Hong Kong, Peoples R China
关键词
Network Intrusion Detection; Intelligent False Alarm Reduction; Ensemble Selection;
D O I
10.1080/18756891.2013.802114
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level.
引用
收藏
页码:626 / 638
页数:13
相关论文
共 50 条
  • [21] A new intrusion detection method using ensemble classification and feature selection
    Pooyan Azizi doost
    Sadegh Sarhani Moghadam
    Edris Khezri
    Ali Basem
    Mohammad Trik
    Scientific Reports, 15 (1)
  • [22] Clustering Enabled Classification using Ensemble Feature Selection for Intrusion Detection
    Salo, Fadi
    Injadat, MohammadNoor
    Moubayed, Abdallah
    Nassif, Ali Bou
    Essex, Aleksander
    2019 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2019, : 276 - 281
  • [23] Identifying False Alarm for Network Intrusion Detection System Using Data Mining and Decision Tree
    Anuar, Nor Badrul
    Sallehudin, Hasimi
    PROCEEDINGS OF THE 7TH WSEAS INTERNATIONAL CONFERENCE ON DATA NETWORKS, COMMUNICATIONS, COMPUTERS (DNCOCO '08): RECENT ADVANCES IN DATA NETWORKS, COMMUNICATIONS, COMPUTERS, 2008, : 22 - 28
  • [24] Identifying False Alarm Rates for Intrusion Detection System with Data Mining
    Sabri, Fatin Norsyafawati Mohd
    Norwawi, Norita Md.
    Seman, Kamaruzzaman
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2011, 11 (04): : 95 - 99
  • [25] Buried fiber intrusion detection sensor with minimal false alarm rates
    Bush, J
    Davis, C
    Davis, P
    Cekorich, A
    McNair, F
    FOURTH PACIFIC NORTHWEST FIBER OPTIC SENSOR WORKSHOP, 1998, 3489 : 30 - 40
  • [26] False Alarm Reduction in Atrial Fibrillation Detection Using Deep Belief Networks
    Taji, Bahareh
    Chan, Adrian D. C.
    Shirmohammadi, Shervin
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2018, 67 (05) : 1124 - 1131
  • [27] Performance Evaluation of Intrusion Detection System Using Anomaly and Signature based algorithms to Reduction False Alarm Rate and Detect Unknown Attacks
    Hussein, Safwan Mawlood
    2016 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE & COMPUTATIONAL INTELLIGENCE (CSCI), 2016, : 1064 - 1069
  • [28] MVPSys: Toward practical multi-view based false alarm reduction system in network intrusion detection
    Li, Wenjuan
    Meng, Weizhi
    Luo, Xiapu
    Kwok, Lam For
    COMPUTERS & SECURITY, 2016, 60 : 177 - 192
  • [29] Enhancing Network Intrusion Detection Using an Ensemble Voting Classifier for Internet of Things
    Farooqi, Ashfaq Hussain
    Akhtar, Shahzaib
    Rahman, Hameedur
    Sadiq, Touseef
    Abbass, Waseem
    SENSORS, 2024, 24 (01)
  • [30] IDENTIFYING FALSE ALARM FOR NETWORK INTRUSION DETECTION SYSTEM USING HYBRID DATA MINING AND DECISION TREE
    Anuar, Nor Badrul
    Sallehudin, Hasimi
    Gani, Abdullah
    Zakari, Omar
    MALAYSIAN JOURNAL OF COMPUTER SCIENCE, 2008, 21 (02) : 101 - 115