Performance evaluation of an immunity-enhancing module for server applications

被引:1
|
作者
Tarao, Mitsunobu [1 ]
Okamoto, Takeshi [1 ]
机构
[1] Kanagawa Inst Technol, 1030 Shimo Ogino, Atsugi, Kanagawa 2420292, Japan
关键词
artificial immune system; machine learning; exploit; shellcode; DoS attack; intrusion detection;
D O I
10.1016/j.procs.2017.08.249
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper focuses on an artificial immunity-enhancing module designed to counter internet-based cyberattacks on high-availability servers. The module consists of innate and adaptive immune functions. The innate immune function detects known and unknown cyberattacks, whereas the adaptive immune function uses a random forest classifier to learn the cyberattack detected by the innate immune function. This paper proposes a new innate immune function that detects two DoS attacks not detected by our previous innate immune function. In addition, a mechanism to maintain learning data is added to the adaptive immune function. The performance of the module was evaluated using four types of attack. Its overall detection accuracy was found to be 87.3%, corresponding to true positive and true negative rates of 78.95% and 95.70%, respectively. Investigation of its detection accuracy for four types of attack showed that a single type of attack degraded the overall detection accuracy. The overheads of the innate and adaptive immune functions were 6% and 4%, respectively, and were little affected by the number of trees in a random forest classifier. The number of learning data required by the adaptive immune function to maintain its high detection accuracy against cyberattacks was approximately 900. (C) 2017 The Authors. Published by Elsevier B.V.
引用
收藏
页码:2165 / 2174
页数:10
相关论文
共 50 条
  • [21] Design and performance analysis of communication module for linux clustering VOD server
    Shin, SY
    Yoo, CG
    Yoo, KJ
    COMPUTER APPLICATIONS IN INDUSTRY AND ENGINEERING, 2003, : 254 - 257
  • [22] Performance evaluation of multi-server queues with station and server vacations
    Gharbi, N
    Ioualalen, M
    2nd International Industrial Simulation Conference 2004, 2004, : 397 - 401
  • [23] Voltage regulator module noise analysis for high-volume server applications
    Matoglu, E
    Pham, N
    Selli, G
    Lai, M
    Connor, S
    Drewniak, JL
    Archambeault, B
    Wang, D
    Kuhn, D
    Hashemi, R
    de Araujo, DN
    Cases, M
    Wilkie, P
    Herrman, P
    Patel, P
    Electrical Performance of Electronic Packaging, 2004, : 267 - 270
  • [24] Server-side performance evaluation of NDN
    Marchal, Xavier
    Cholez, Thibault
    Festor, Olivier
    PROCEEDINGS OF THE 2016 3RD ACM CONFERENCE ON INFORMATION-CENTRIC NETWORKING (ACM-ICN '16), 2016, : 148 - 153
  • [25] Server Consolidation Using OpenVZ: Performance Evaluation
    Ahmed, Mohuiddin
    Zahda, Showayb
    Abbas, Majed
    2008 11TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY: ICCIT 2008, VOLS 1 AND 2, 2008, : 180 - 185
  • [26] Design and performance evaluation of a multimedia Web server
    Lee, YB
    Wong, PC
    JOURNAL OF VISUAL COMMUNICATION AND IMAGE REPRESENTATION, 1998, 9 (03) : 183 - 193
  • [27] Performance evaluation of a prototype distributed NFS server
    Avila, RB
    Navaux, POA
    Lombard, P
    Lebre, A
    Denneulin, Y
    16TH SYMPOSIUM ON COMPUTER ARCHITECTURE AND HIGH PERFORMANCE COMPUTING, PROCEEDINGS, 2004, : 100 - 105
  • [28] Performance modeling and evaluation of web server systems
    Fujita, Y
    Murata, M
    Miyahara, H
    ELECTRONICS AND COMMUNICATIONS IN JAPAN PART II-ELECTRONICS, 2000, 83 (12): : 12 - 23
  • [29] Performance evaluation module for textile materials
    Bachman, Jean Marie
    Barbieri, Marco
    Dumitrescu, Iuliana
    INDUSTRIA TEXTILA, 2011, 62 (02): : 105 - 107
  • [30] Implementation of the performance evaluation system for the NTP server
    Nakashima, T
    Oshima, S
    Nakashima, A
    2003 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS, AND SIGNAL PROCESSING, VOLS 1 AND 2, CONFERENCE PROCEEDINGS, 2003, : 828 - 831