Advanced sensor fusion technique for enhanced Intrusion Detection

被引:4
作者
Thomas, Ciza
Balakrishnan, Narayanaswamy
机构
来源
ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS | 2008年
关键词
Intrusion Detection Systems (IDS); Data-Dependent fusion (DD fusion); f-score; sensor fusion; Neural Network;
D O I
10.1109/ISI.2008.4565049
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The existing Intrusion Detection Systems are of varied type and hence show distinct preferences in detecting certain types of attacks with improved accuracy, while performing moderately on the other types. With the advances in sensor fusion, it has become possible to obtain a more reliable and accurate decision for a wider class of attacks, by combining the decisions of multiple Intrusion Detection Systems. In this paper, an architecture using Data-Dependent decision fusion is proposed. The method gathers an in-depth understanding about the input traffic and also the behavior of the individual Intrusion Detection Systems by means of a Neural Network supervised learner unit. This information is used to fine-tune the fusion unit, since the fusion depends on the input feature vector. For illustrative purposes three Intrusion Detection Systems PHAD, ALAD, and Snort have been considered using the DARPA 1999 dataset in order to validate the proposed architecture. The overall performance of the proposed sensor fusion system shows considerable improvement in comparison to the performance of individual Intrusion Detection Systems.
引用
收藏
页码:173 / 178
页数:6
相关论文
共 28 条
[1]  
Anderson J.P., 1980, Computer security threat monitoring and surveillance
[2]  
[Anonymous], Intrusion detection evaluation dataset (CIC-IDS2017)
[3]  
[Anonymous], SNORT MANUAL
[4]  
[Anonymous], DARPA intrusion detection data sets
[5]  
BASS T, 1999, IRIS NAT S
[6]  
CUPPENS F, 2002, P 2002 IEEE S SEC PR
[7]  
DAIN OM, 2001, IEEE WORKSH INF ASS
[8]  
Debar H., 2001, AGGREGATION CORRELAT
[9]   AN INTRUSION-DETECTION MODEL [J].
DENNING, DE .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1987, 13 (02) :222-232
[10]  
DIDACI L, 2002, INT C PATT REC