Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection

被引:40
|
作者
Meng, Yuxin [1 ]
Kwok, Lam-For [1 ]
机构
[1] City Univ Hong Kong, Dept Comp Sci, Kowloon, Hong Kong, Peoples R China
关键词
Network Intrusion Detection; Intelligent False Alarm Reduction; Ensemble Selection;
D O I
10.1080/18756891.2013.802114
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level.
引用
收藏
页码:626 / 638
页数:13
相关论文
共 50 条
  • [41] Enhancing IoT Network Security Using Feature Selection for Intrusion Detection Systems
    Almohaimeed, Muhannad
    Albalwy, Faisal
    APPLIED SCIENCES-BASEL, 2024, 14 (24):
  • [42] A Multi-Agent-based Approach to Improve Intrusion Detection Systems False Alarm Ratio by Using Honeypot
    Khosravifar, Babak
    Gomrokchi, Maziar
    Bentahar, Jamal
    2009 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS: WAINA, VOLS 1 AND 2, 2009, : 97 - +
  • [43] Network Intrusion Detection and Comparative Analysis Using Ensemble Machine Learning and Feature Selection
    Das, Saikat
    Saha, Sajal
    Priyoti, Annita Tahsin
    Roy, Etee Kawna
    Sheldon, Frederick T. T.
    Haque, Anwar
    Shiva, Sajjan
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (04): : 4821 - 4833
  • [44] False alarm minimization techniques in signature-based intrusion detection systems: A survey
    Hubballi, Neminath
    Suryanarayanan, Vinoth
    COMPUTER COMMUNICATIONS, 2014, 49 : 1 - 17
  • [45] Intrusion Detection Using Ensemble Wrapper Filter Based Feature Selection with Stacking Model
    Karthikeyan, D.
    Raj, V. Mohan
    Senthilkumar, J.
    Suresh, Y.
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2023, 35 (01): : 645 - 659
  • [46] Enhancing intrusion detection with feature selection and neural network
    Wu, Chunhui
    Li, Wenjuan
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2021, 36 (07) : 3087 - 3105
  • [47] Constant False Alarm Rate Anomaly-Based Approach for Network Intrusion Detection
    AlShaalan, Rayan
    AsSadhan, Basil
    Al-Muhtadi, Jalal
    Bin-Abbas, Hesham
    Abd El-Samie, Fathi
    Alshebeili, Saleh
    2013 10TH INTERNATIONAL CONFERENCE ON HIGH CAPACITY OPTICAL NETWORKS AND ENABLING TECHNOLOGIES (HONET-CNS), 2013, : 141 - 145
  • [48] An Ensemble Intrusion Detection System based on Acute Feature Selection
    Hariprasad, S.
    Deepa, T.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (03) : 8267 - 8280
  • [49] A Review on Feature Selection and Ensemble Techniques for Intrusion Detection System
    Torabi, Majid
    Udzir, Nur Izura
    Abdullah, Mohd Taufik
    Yaakob, Razali
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (05) : 538 - 553
  • [50] Evaluation and Selection Models for Ensemble Intrusion Detection Systems in IoT
    Alghamdi, Rubayyi
    Bellaiche, Martine
    IOT, 2022, 3 (02): : 285 - 314