Evolving High-Speed, Easy-to-Understand Network Intrusion Detection Rules with Genetic Programming

被引:0
|
作者
Orfila, Agustin [1 ]
Estevez-Tapiador, Juan M. [1 ]
Ribagorda, Arturo [1 ]
机构
[1] Univ Carlos III Madrid, Leganes 28911, Spain
来源
APPLICATIONS OF EVOLUTIONARY COMPUTING, PROCEEDINGS | 2009年 / 5484卷
关键词
ANOMALY DETECTION;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An ever-present problem in intrusion detection technology is how to construct the patterns of (good, bad or anomalous) behaviour upon which an engine have to make decisions regarding the nature of the activity observed in a, system. This has traditionally been one of the central areas of research in the field, and most of the solutions proposed so far have relied in one way or another upon sonic form of data mining-with the exception, of course, of human-constructed patterns. In this paper, we explore the use of Genetic Programming (GP) for such a purpose. Our approach is not new in some aspects, as CP has already been partially explored in the past. Here we show that GP can offer at least two advantages over other classical mechanisms: it can produce very lightweight detection rules (something of extreme importance for highspeed networks or resource-constrained applications) and the simplicity of the patterns generated allows to easily Understand the semantics of the underlying attack.
引用
收藏
页码:93 / 98
页数:6
相关论文
共 50 条
  • [1] Intrusion detection system for high-speed network
    Yang, W
    Fang, BX
    Liu, B
    Zhang, HL
    COMPUTER COMMUNICATIONS, 2004, 27 (13) : 1288 - 1294
  • [2] High-speed string matching for network intrusion detection
    Soewito, Benfano
    Mahajan, Atul
    Weng, Ning
    Wang, Haibo
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2009, 3 (04) : 319 - 339
  • [3] Study on high-speed network intrusion detection based on network processor
    Computer Network Key Lab., South China University of Technology, Guangzhou 510640, China
    不详
    Zhongshan Daxue Xuebao, 2006, SUPPL. (31-34):
  • [4] Evaluating Network Intrusion Detection Systems for High-Speed Networks
    Hu, Qinwen
    Asghar, Muhammad Rizwan
    Brownlee, Nevil
    2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2017, : 402 - 407
  • [5] Study of High-Speed Processing for Network Intrusion Detection System
    Liu, Hui
    MATERIALS AND MANUFACTURING TECHNOLOGY, PTS 1 AND 2, 2010, 129-131 : 1410 - 1414
  • [6] Intrusion detection technology research based high-speed network
    Bo, S
    Ming, Y
    Jie, L
    PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PDCAT'2003, PROCEEDINGS, 2003, : 206 - 210
  • [7] High-Speed Railway Clearance Intrusion Detection with Improved SSD Network
    Guo, Baoqing
    Shi, Jiafeng
    Zhu, Liqiang
    Yu, Zujun
    APPLIED SCIENCES-BASEL, 2019, 9 (15):
  • [8] Network intrusion detection systems in high-speed traffic in computer networks
    Bul'ajoul, Waleed
    James, Anne
    Pannu, Mandeep
    2013 IEEE 10TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2013, : 168 - 175
  • [9] A stateful real time intrusion detection system for high-speed network
    Sourour, Meharouech
    Adel, Bouhoula
    Tarek, Abbes
    21st International Conference on Advanced Networking and Applications, Proceedings, 2007, : 404 - 411
  • [10] One Data Preprocessing Method in High-speed Network Intrusion Detection
    Li, Kunlun
    Zhang, Zhenxing
    Liu, Ming
    ICWMMN 2010, PROCEEDINGS, 2010, : 60 - 63