Newest Collaborative and Hybrid Network Intrusion Detection Framework Based on Suricata and Isolation Forest Algorithm

被引:5
作者
Chiba, Zouhair [1 ]
Abghour, Noreddine [1 ]
Moussaid, Khalid [1 ]
El Omri, Amina [1 ]
Rida, Mohamed [1 ]
机构
[1] Hassan II Univ Casablanca, Fac Sci, LIMSAD Labs, Casablanca 20100, Morocco
来源
4TH INTERNATIONAL CONFERENCE ON SMART CITY APPLICATIONS (SCA' 19) | 2019年
关键词
Network intrusion detection system; Signature detection; Anomaly detection; Hybrid IDS; Suricata; Isolation forest algorithm; ANOMALY DETECTION;
D O I
10.1145/3368756.3369061
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the advent of digital technology, computer networks have developed rapidly at an unprecedented pace contributing tremendously to social and economic development. They have become the backbone for all critical sectors and all the top Multi-National companies. Unfortunately, security threats for computer networks have increased dramatically over the last decade being much brazen and bolder. Indeed, intrusions or attacks can lead to irreparable damages, information leakage and significant financial losses. Hence, there is a great need for an effective Network Intrusion Detection System (NIDS). In the current study, we propose a hybrid NIDS to detect network attacks in the network environment by monitoring network traffic, thereby achieving a solid line of protection against inside and outside intruders and maintaining performance and service quality. In our NIDS framework, we use Suricata as a signature based detection to uncover known attacks, while for detecting network anomaly, we use Isolation Forest Algorithm (IFA). By applying Suricata prior to the IFA classifier, IFA has to detect only unknown attacks. Therefore, detection time is reduced and computational power is saved. Suricata is an open source IDS, which has been advanced as a multi-threaded alternative to popular Snort IDS. The major benefits of a multi-threaded design is that it offers increased speed and efficiency in network traffic analysis and can also help divide up the IDS workload based on where the processing needs are. Consequently, Suricata shows an increase in accuracy and system performance over the de facto standard, single threaded NIDS Snort. While, IFA is one of the newest approaches to detect anomalies/outliers, which introduces the use of isolation as a more effective and efficient means to recognize anomalies than the popularly used basic distance and density measures. In fact, IFA uses no distance or density measures to identify outliers, this eliminates major computational cost of distance calculation in all distance-based and density-based algorithms. Additionally, IFA has a low constant in its computational complexity. Moreover, in this framework, the NIDSs operate in collaborative way to oppose attacks by sharing alerts stored in central log. In this way, unknown attacks that were detected by any NIDS can easily be detected by others IDSs. This also helps to reduce computational cost for detecting intrusions at others NIDSs, and improve detection rate in overall the network environment.
引用
收藏
页数:11
相关论文
共 42 条
  • [1] Abe N., 2006, P 12 ACM SIGKDD INT, P504, DOI DOI 10.1145/1150402.1150459
  • [2] Ahmad Azuan, 2017, International Journal of Communication Networks and Information Security, V9, P67
  • [3] ALBIN E, 2011, THESIS
  • [4] Alom MZ, 2015, PROC NAECON IEEE NAT, P339, DOI 10.1109/NAECON.2015.7443094
  • [5] Another Fuzzy Anomaly Detection System Based on Ant Clustering Algorithm
    Aminanto, Muhamad Erza
    Kim, HakJu
    Kim, Kyung-Min
    Kim, Kwangjo
    [J]. IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2017, E100A (01) : 176 - 183
  • [6] BAHNSEN AC, 2016, BENEFITS ANOMALY DET
  • [7] Bay S.D., 2003, KDD 03 P 9 ACM SIGKD, P29, DOI [DOI 10.1145/956750.956758, 10.1145/956750.956758]
  • [8] LOF: Identifying density-based local outliers
    Breunig, MM
    Kriegel, HP
    Ng, RT
    Sander, J
    [J]. SIGMOD RECORD, 2000, 29 (02) : 93 - 104
  • [9] Isolation Forest as an Alternative Data-Driven Mineral Prospectivity Mapping Method with a Higher Data-Processing Efficiency
    Chen, Yongliang
    Wu, Wei
    [J]. NATURAL RESOURCES RESEARCH, 2019, 28 (01) : 31 - 46
  • [10] CHIBA Z, 2018, P 3 INT C SMART CITY, P507, DOI DOI 10.1007/978-3-030-11196-0_43