Modified parallel random forest for intrusion detection systems

被引:21
作者
Masarat, Saman [1 ]
Sharifian, Saeed [2 ]
Taheri, Hassan [2 ]
机构
[1] Amirkabir Univ Technol, Switching & Network Lab, Tehran Polytech, Tehran 15914, Iran
[2] Amirkabir Univ Technol, Dept Elect & Elect, Tehran Polytech, Tehran 15914, Iran
关键词
Random forest algorithm; Intrusion detection system; Classifier ensemble; Decision tree; Hadoop; CENTERS; IDS;
D O I
10.1007/s11227-016-1727-6
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection system (IDS) is one of the important elements for providing the security in networks. Increasing the number of network-based applications on the one hand and increasing the data volumes on the other hand forced the designers to conduct some research on the novel methods for improving network security. One of the recent efforts to improve IDS performance is developing the machine learning algorithms. Random forest is one of the powerful algorithms employed in data mining. It operates based on classifier fusion principles and is implemented as detection engine in some anomaly-based IDSs. In this paper, we present a novel parallel random forest algorithm for intrusion detection systems. The original random forest algorithm has some weaknesses in feature selection, selecting efficient numbers of classifiers, number of random features for training and also in combination steps. In this research we investigate aforementioned challenges and propose solutions for them. The simulation results show the superiority of our method regarding performance, scalability and cost of misclassified samples in our method in comparison with the original random forest algorithm and Hadoop-based version of the random forest.
引用
收藏
页码:2235 / 2258
页数:24
相关论文
共 66 条
[1]  
Abadeh M. S., 2008, COMPUTER, V35, P37
[2]  
Abadi M., 2006, IRANIAN J ELECT ELEC, V2, P106
[3]  
Abraham A., 2007, Int. J. Netw. Secur, V4, P328
[4]  
Aickelin U., 2014, SEARCH METHODOLOGIES, P187
[5]  
Al-Mamory SO, 2007, ELE COM ENG, P69
[6]  
Alipour H, 2008, P WORLD C ENG
[7]   RT-UNNID: A practical solution to real-time network-based intrusion detection using unsupervised neural networks [J].
Amini, Morteza ;
Jalili, Rasool ;
Shahriari, Hamid Reza .
COMPUTERS & SECURITY, 2006, 25 (06) :459-468
[8]  
Axelsson S, 2000, taxonomy. TechIntrusion detection systems: A survey and nical Report, P1
[9]  
Bace R., 2001, NIST Special Publication on Intrusion Detection Systems
[10]   Random forests [J].
Breiman, L .
MACHINE LEARNING, 2001, 45 (01) :5-32