Big data analytics by automated generation of fuzzy rules for Network Forensics Readiness

被引:14
作者
Shalaginov, Andrii [1 ]
Franke, Katrin [1 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Cyber & Informat Secur, Norwegian Informat Secur Lab, Trondheim, Norway
关键词
Big data; Soft Computing; Neuro-Fuzzy; Intrusion detection; Self-organizing feature maps; Computational forensics; NEURO-FUZZY;
D O I
10.1016/j.asoc.2016.10.029
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Analysis of large-scale traffic dumps in Network Forensics can be a complex and non-trivial problem. This is an important step in collecting evidences and making threat intelligence to foresee new illegal activities. Machine Learning comes into help to automatically support decision of forensics expert. Furthermore, application in live systems may bring additional obstacles related to forensics readiness and knowledge discovery. We believe that it can be mitigated by means of Neuro-Fuzzy, a fusion of human-understandable model and automated data analytic. This method includes optimal unsupervised grouping of samples with so-called Self-Organizing Features Map and fuzzy rules tuning by Artificial Neural Network. In this work we propose improvements of the methods that makes it possible to extract fewer fuzzy rules in a faster manner. The new method has two advantages in comparison to existing. First, we improve the estimation of fuzzy patches. Second, parameterization that represents the data by incorporating additional ellipse compactness information. By using ellipse rotation and flattering information, the membership functions can be derived. To even further enhance the generalization of the method, the bootstrap aggregation was tested during the grouping phase. Finally, the method has been assessed on the intrusion detection dataset with a five millions samples with classification accuracy 94% using only 12 rules. (C) 2016 Elsevier B.V. All rights reserved.
引用
收藏
页码:359 / 375
页数:17
相关论文
共 59 条
[1]   Dynamic self-organizing maps with controlled growth for knowledge discovery [J].
Alahakoon, D ;
Halgamuge, SK ;
Srinivasan, B .
IEEE TRANSACTIONS ON NEURAL NETWORKS, 2000, 11 (03) :601-614
[2]  
[Anonymous], ADV SELF ORGANIZING
[3]  
[Anonymous], BANDWIDTH PACKETS PE
[4]  
[Anonymous], 2009 52 IEEE INT MID
[5]  
[Anonymous], 2013 43 ANN IEEE IFI
[6]  
[Anonymous], 2008, OFFENTLICHEN RECHTS
[7]  
[Anonymous], WSEAS INT C P MATH C
[8]  
[Anonymous], TECH REP
[9]  
[Anonymous], P 2015 C INT FUZZ SY
[10]  
[Anonymous], 2013 IEEE 13 INT C D