Adaptive False Alarm Filter Using Machine Learning in Intrusion Detection

被引:0
|
作者
Meng, Yuxin [1 ]
Kwok, Lam-for [1 ]
机构
[1] City Univ Hong Kong, Dept Comp Sci, Hong Kong, Hong Kong, Peoples R China
关键词
Intrusion detection; False alarm; Machine learning; Adaptive system;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intrusion detection systems (IDSs) have been widely deployed in organizations nowadays as the last defense for the network security. However, one of the big problems of these systems is that a large amount of alarms especially false alarms will be produced during the detection process, which greatly aggravates the analysis workload and reduces the effectiveness of detection. To mitigate this problem, we advocate that the construction of a false alarm filter by utilizing machine learning schemes is an effective solution. In this paper, we propose an adaptive false alarm filter aiming to filter out false alarms with the best machine learning algorithm based on distinct network contexts. In particular, we first compare with six specific machine learning schemes to illustrate their unstable performance. Then, we demonstrate the architecture of our adaptive false alarm filter. The evaluation results show that our approach is effective and encouraging in real scenarios.
引用
收藏
页码:573 / 584
页数:12
相关论文
共 50 条
  • [1] Adaptive SVDD-based Learning for False Alarm Reduction in Intrusion Detection
    Kenaza, Tayeb
    Labed, Abdenour
    Boulahia, Yacine
    Sebehi, Mohcen
    2015 12TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (ICETE), VOL 4, 2015, : 405 - 412
  • [2] Adaptive Intrusion Detection Using Machine Learning
    Neethu, B.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (03): : 118 - 124
  • [3] Improving False Alarm Rate in Intrusion Detection Systems Using Hadoop
    Mukund, Y. R.
    Nayak, Sunil S.
    Chandrasekaran, K.
    2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 837 - 843
  • [4] A Machine Learning Approach to False Alarm Detection for Critical Arrhythmia Alarms
    Wang, Xing
    Gao, Yifeng
    Lin, Jessica
    Rangwala, Huzefa
    Mittu, Ranjeev
    2015 IEEE 14TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2015, : 202 - 207
  • [5] Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
    Meng, Yuxin
    Kwok, Lam-For
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2013, 6 (04) : 626 - 638
  • [6] Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
    Yuxin Meng
    Lam-For Kwok
    International Journal of Computational Intelligence Systems, 2013, 6 : 626 - 638
  • [7] Adaptive machine learning-based alarm reduction via edge computing for distributed intrusion detection systems
    Wang, Yu
    Meng, Weizhi
    Li, Wenjuan
    Liu, Zhe
    Liu, Yang
    Xue, Hanxiao
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (19):
  • [8] An Adaptive Ensemble Machine Learning Model for Intrusion Detection
    Gao, Xianwei
    Shan, Chun
    Hu, Changzhen
    Niu, Zequn
    Liu, Zhen
    IEEE ACCESS, 2019, 7 : 82512 - 82521
  • [9] Sensor Fusion for Intrusion Detection Under False Alarm Constraints
    Pugh, Matthew
    Brewer, Jerry
    Kvam, Jacques
    2015 IEEE SENSORS APPLICATIONS SYMPOSIUM (SAS), 2015, : 377 - 382
  • [10] Network specific false alarm reduction in intrusion detection system
    Hubballi, Neminath
    Biswas, Santosh
    Nandi, Sukumar
    SECURITY AND COMMUNICATION NETWORKS, 2011, 4 (11) : 1339 - 1349