ICDF: Intrusion collaborative detection framework based on confidence

被引:4
作者
Wang, Zhi [1 ]
Shao, Leshi [1 ]
Cheng, Kai [1 ]
Liu, Yuanzhao [1 ]
Jiang, Jianan [2 ]
Nie, Yuanping [3 ]
Li, Xiang [3 ]
Kuang, Xiaohui [3 ]
机构
[1] Nankai Univ, Coll Cyber Sci, Tianjin, Peoples R China
[2] Guangzhou Univ, Inst Artificial & Intelligence, Guangzhou 510006, Peoples R China
[3] Natl Key Lab Sci & Technol Informat Syst Secur, Beijing 100101, Peoples R China
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
confidence; intrusion detection; IVAP; model collaboration; ALGORITHMS;
D O I
10.1002/int.22877
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many machine-learning-based intrusion detection methods have been proposed, however there is a lack of collaboration among these methods. Faced with a cascade of malicious behaviors and various running environments, coupled with the endless emergence of new malicious activities, it is difficult for us to choose an algorithm manually that is suitable for all scenarios. In addition, usually the binary detection models are applied that only "normal" or "abnormal" decision is made, and it is difficult for us to know how much confidence we have in the prediction model. In this study, we propose an intrusion collaborative detection framework (ICDF), an ICDF that allows heterogeneous detection models to effectively work together which have complementary expertise. A multialgorithm model ensemble learning method with confidence interval is adopted. In this process, each algorithm model only makes prediction judgments on its own credible probability interval and refuses to predict outside the interval. The final result is generated by voting based on the confidence of multiple models. Ten detection algorithms were tested on three different data sets. Compared with different single algorithms, ICDF could achieve high precision and recall rate, and the best F1 scores.
引用
收藏
页码:7180 / 7199
页数:20
相关论文
共 50 条
  • [41] An Intrusion Detection Framework for the Smart Grid
    Ullah, Imtiaz
    Mahmoud, Qusay H.
    2017 IEEE 30TH CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2017,
  • [42] An Evaluation Framework for Intrusion Detection Dataset
    Gharib, Amirhossein
    Sharafaldin, Iman
    Lashkari, Arash Habibi
    Ghorbani, Ali A.
    2016 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SECURITY (ICISS), 2014, : 41 - 45
  • [43] A flow-based intrusion detection framework for internet of things networks
    Leonel Santos
    Ramiro Gonçalves
    Carlos Rabadão
    José Martins
    Cluster Computing, 2023, 26 : 37 - 57
  • [44] Intrusion Detection Framework for CAN Networks Based on Evidence Deep Learning
    Shi, Qin
    Li, Zhiwei
    Cheng, Teng
    Zhang, Qiang
    Wang, Wenchong
    Qiche Gongcheng/Automotive Engineering, 2024, 46 (11): : 2039 - 2045
  • [45] A clustered learning framework for host based intrusion detection in container environment
    Shen, Jingfei
    Zeng, Fanping
    Zhang, Weikang
    Tao, Yufan
    Tao, Shengkun
    2022 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2022, : 409 - 414
  • [46] Game Theoretic Framework for Reputation-based Distributed Intrusion Detection
    Bradai, Amira
    Afifi, Hossam
    2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 558 - 563
  • [47] A flow-based intrusion detection framework for internet of things networks
    Santos, Leonel
    Goncalves, Ramiro
    Rabadao, Carlos
    Martins, Jose
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2023, 26 (01): : 37 - 57
  • [48] A novel Rule Based Intrusion Detection Framework for Wireless Sensor Networks
    Eswari, T.
    Vanitha, V.
    2013 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2013, : 1019 - 1022
  • [49] An integrated intrusion detection framework based on subspace clustering and ensemble learning
    Zhu, Jingyi
    Liu, Xiufeng
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 115
  • [50] An ensemble-based evolutionary framework for coping with distributed intrusion detection
    Gianluigi Folino
    Clara Pizzuti
    Giandomenico Spezzano
    Genetic Programming and Evolvable Machines, 2010, 11 : 131 - 146