A homogeneous ensemble based dynamic artificial neural network for solving the intrusion detection problem

被引:13
作者
Al-Daweri, Muataz Salam [1 ]
Abdullah, Salwani [1 ]
Ariffin, Khairul Akram Zainol [2 ]
机构
[1] Univ Kebangsaan Malaysia, Ctr Artificial Intelligence Technol, Bangi 43600, Malaysia
[2] Univ Kebangsaan Malaysia, Ctr Cyber Secur, Bangi 43600, Malaysia
关键词
Classification; Optimization; Filter-wrapper feature selection; Dynamic artificial neural network; Intrusion detection system; Critical infrastructure; FEATURE-SELECTION; DETECTION SYSTEMS; OPTIMIZATION ALGORITHM; CUTTLEFISH ALGORITHM; GENETIC ALGORITHM; EVOLUTIONARY; MACHINE;
D O I
10.1016/j.ijcip.2021.100449
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network security is a mechanism of protecting the usability and integrity of any given network and its transmitted data. Network security's effectiveness is crucial to the network environment to ensure it is free from any threat, especially in the critical infrastructure (CI). The supervisory control and data acquisition systems in the CI are getting more connected to the internet, putting them in serious security concerns. Any malicious attack against these systems could cause considerable human, economic, and material damages. Thus, it leads to the emergence of the intrusion detection system (IDS). Theoretically, a modern IDS must handle a large amount of data with high accuracy. Ensemble-based, hybrid-based methods and their distinguished applications are a promising way to solve these issues. The efficiency of the IDS is mainly dependent on the selected data features and the used classification method. The artificial neural network (ANN) has been applied in various fields, but it requires adjustment on few parameters to work effectively. This study proposes a homogeneous ensemble based on single-class dynamic ANN (HOE-DANN). Each dynamic ANN (DANN) is optimized by a filter-wrapper method using a modified discrete cuttlefish algorithm based on rough set theory, and a migration-strategy based cuttlefish algorithm. Both algorithms simultaneously optimize the features, ANN structure, weights, and biases for creating the DANN. However, the threshold value of the ensemble model was set using the hill-climbing algorithm. The experiments were applied to well-known benchmark datasets, namely the KDD99, UNSW-NB15, and gas pipeline data logs (GPDL). The results show that the HOE-DANN outperforms the single model based on the DANN. Additionally, a comparison with several state-of-the-art methods has shown that the proposed method offers superior performance in terms of the detection rate (DR), false alarm rate (FAR), and classification accuracy (ACC). The HOE-DANN model was able to achieve DR of 97.47%, FAR of 2.25%, and ACC of 97.52% using the KDD99 dataset, DR of 99.93%, FAR of 13.13%, and ACC of 94.08% using the UNSW-NB15 dataset, and DR of 98.08%, FAR of 2.69%, and ACC of 94.50% using the GPDL dataset. (c) 2021 Elsevier B.V. All rights reserved.
引用
收藏
页数:23
相关论文
共 81 条
[1]  
Abdul-Rahman S., 2010, Proceedings 10th International Conference on Intelligent Systems Design and Applications (ISDA 2010), P1009, DOI 10.1109/ISDA.2010.5687056
[2]   A survey of intrusion detection systems based on ensemble and hybrid classifiers [J].
Aburomman, Abdulla Amin ;
Reaz, Mamun Bin Ibne .
COMPUTERS & SECURITY, 2017, 65 :135-152
[3]  
Abusnaina AA, 2013, PROC INT CONF COMP, P78
[4]   A Migration-Based Cuttlefish Algorithm With Short-Term Memory for Optimization Problems [J].
Al Daweri, Muataz Salam ;
Abdullah, Salwani ;
Ariffin, K. A. Zainol .
IEEE ACCESS, 2020, 8 :70270-70292
[5]   An Analysis of the KDD99 and UNSW-NB15 Datasets for the Intrusion Detection System [J].
Al-Daweri, Muataz Salam ;
Ariffin, Khairul Akram Zainol ;
Abdullah, Salwani ;
Senan, Mohamad Firham Efendy Md .
SYMMETRY-BASEL, 2020, 12 (10) :1-32
[6]   Real-time multi-agent system for an adaptive intrusion detection system [J].
Al-Yaseen, Wathiq Laftah ;
Othman, Zulaiha Ali ;
Nazri, Mohd Zakree Ahmad .
PATTERN RECOGNITION LETTERS, 2017, 85 :56-64
[7]   Multi-level hybrid support vector machine and extreme learning machine based on modified K-means for intrusion detection system [J].
Al-Yaseen, Wathiq Laftah ;
Othman, Zulaiha Ali ;
Nazri, Mohd Zakree Ahmad .
EXPERT SYSTEMS WITH APPLICATIONS, 2017, 67 :296-303
[8]  
Ali GA, 2011, COMM COM INF SC, V181, P777
[9]   Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model [J].
Aljawarneh, Shadi ;
Aldwairi, Monther ;
Yassein, Muneer Bani .
JOURNAL OF COMPUTATIONAL SCIENCE, 2018, 25 :152-160
[10]  
Almansor M., 2018, J MULTIDISCIP ENG SC, V4, P2458