Wavelets Based Anomaly-Based Detection System or J48 and Naive Bayes Based Signature-Based Detection System: A Comparison

被引:5
作者
Kaur, Gagandeep [1 ]
Bansal, Amit [1 ]
Agarwal, Arushi [1 ]
机构
[1] Jaypee Inst Informat Technol, Dept CSE & IT, Noida 201307, India
来源
AMBIENT COMMUNICATIONS AND COMPUTER SYSTEMS, RACCCS 2017 | 2018年 / 696卷
关键词
D O I
10.1007/978-981-10-7386-1_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems are divided into two categories, namely signature-based detection systems (SbDS) and anomaly-based detection systems (AbDS). In this paper, we have compared results of detection techniques for SbDS and AbDS for big datasets. Under AbDS, wavelets have been used as a signal processing tool to compute Hurst Index (H), used as a measure for computing degree of self-similarity in network traffic. Deviations beyond threshold were used to detect presence of network anomalies. Under SbDS, two main classification techniques based on J48 and Naive Bayes have been used to explore the possibilities of having best achievable accuracy with least number of parameters from a big dataset of 41 features. The results of both methodologies have been analyzed for choosing appropriate technique under given constraints.
引用
收藏
页码:213 / 224
页数:12
相关论文
共 17 条
[1]   Wavelet analysis of long-range-dependent traffic [J].
Abry, P ;
Veitch, D .
IEEE TRANSACTIONS ON INFORMATION THEORY, 1998, 44 (01) :2-15
[2]  
Alshamrani H, 2016, IEEE 17 INT C HIGH P
[3]  
[Anonymous], 2009, 2 IEEE S COMP INT SE
[4]  
[Anonymous], 2016, P 7 ANN C INFORM TEC, DOI DOI 10.1109/IEMCON.2016.7746286
[5]  
Basil A, ANOMALY DETECTION BA
[6]  
Csubak D., 2016, ACTA POLYTECHNICA HU, V13
[7]  
Deshmukh D. H, 2015, INT C COMM INF COMP
[8]  
Goeschel K., 2016, SE C
[9]  
Katkar V, 2015, INT C COMP COMM CONT
[10]   A multi scale approach to distinguish flash crowds from PDDoS attacks [J].
Kaur, Gagandeep ;
Saxena, Vikas ;
Gupta, J.P. .
International Journal of Information and Communication Technology, 2014, 6 (02) :213-238