An improved ensemble approach for effective intrusion detection

被引:1
作者
Gulshan Kumar
机构
[1] Shaheed Bhagat Singh State Technical Campus,Department of Computer Applications
来源
The Journal of Supercomputing | 2020年 / 76卷
关键词
Genetic algorithm; Intrusion; Intrusion detection system; Machine learning; MOGA; Neural networks;
D O I
暂无
中图分类号
学科分类号
摘要
Nowadays, one critical challenge of cybersecurity administrators is the protection of online resources from network intrusions. Despite several academic and industry research initiatives, full protection of online resources from these network intrusions is not feasible. Therefore, several techniques have been developed that use network audit data for accurate detection of network intrusions effectively and efficiently and are used in network intrusion detection systems (NIDSs). But, most of NIDSs reported low detection accuracy with high false alarm rate and provide a single solution that lacks in classification trade-offs. In this paper, the authors present a hybrid approach of multi-objective genetic algorithm and neural networks for creating a set of ensemble solutions for detecting network intrusions effectively. The proposed approach works in two phases that initially creates a set of non-dominating solutions or Pareto optimal solutions of base techniques and then creates ensemble solutions. In the outcome of individual solutions or models in the ensemble are aggregated using most popular method of majority voting. The proposed hybrid approach is evaluated using benchmark datasets of NSL_KDD and ISCX-2012 datasets for intrusion detection. The evaluation results using benchmark datasets demonstrate that the proposed hybrid approach enables detecting network intrusions effectively as compared to conventional ensemble approaches, namely bagging and boosting. The resultant ensemble solutions are non-dominating and provide classification trade-offs for cybersecurity administrators. The results also show that the proposed hybrid approach detects both minority and majority intrusion types accurately. The proposed hybrid approach demonstrated a detection accuracy of 97% and 88% with FPR of 2.4% and 2% for ISCX-2012 and NSL_KDD datasets, respectively.
引用
收藏
页码:275 / 291
页数:16
相关论文
共 95 条
[1]  
Chebrolu S(2005)Feature deduction and ensemble design of intrusion detection systems Comput Secur 24 295-307
[2]  
Abraham A(2000)A fast elitist non-dominated sorting genetic algorithm for multi-objective optimization: NSGA-II Lect Notes Comput Sci 1917 849-858
[3]  
Thomas J(2002)A computationally efficient evolutionary algorithm for real-parameter optimization Evolut Comput 10 371-395
[4]  
Deb K(2019)A multi-objective evolutionary fuzzy system to obtain a broad and accurate set of solutions in intrusion detection systems Soft Comput 23 1321-1336
[5]  
Agrawal S(2018)Network anomaly detection system using genetic algorithm and fuzzy logic Expert Syst Appl 92 390-402
[6]  
Pratap A(2006)Evolutionary multiobjective optimization for the design of fuzzy rule-based ensemble classifiers Int J Hybrid Intell Syst 3 129-145
[7]  
Meyarivan T(2010)Iterative boolean combination of classifiers in the ROC space: an application to anomaly detection with HMMs Pattern Recognit 43 2732-2752
[8]  
Deb K(2012)Adaptive ROC-based ensembles of HMMs applied to anomaly detection Pattern Recognit 45 208-230
[9]  
Anand A(2012)The use of multi-objective genetic algorithm based approach to create ensemble of ANN for intrusion detection Int J Intell Sci 2 115-127
[10]  
Joshi D(2010)An empirical comparative analysis of feature reduction methods for intrusion detection Int J Inf Telecommun Technol 1 44-51