A Lattice based Nearest Neighbor Classifier for Anomaly Intrusion Detection

سال انتشار: 1392
نوع سند: مقاله ژورنالی
زبان: انگلیسی
مشاهده: 484

فایل این مقاله در 10 صفحه با فرمت PDF قابل دریافت می باشد

استخراج به نرم افزارهای پژوهشی:

لینک ثابت به این مقاله:

شناسه ملی سند علمی:

JR_JACR-4-4_005

تاریخ نمایه سازی: 16 شهریور 1395

چکیده مقاله:

As networking and communication technology becomes more widespread, thequantity and impact of system attackers have been increased rapidly. Themethodology of intrusion detection (IDS) is generally classified into two broadcategories according to the detection approaches: misuse detection and anomalydetection. In misuse detection approach, abnormal system behavior is defined atfirst, and then any other behavior is defined as normal behavior. The main goal ofthe anomaly detection approach is to construct a model representing normalactivities. Then, any deviation from this model can be considered as an anomaly,and recognized to be an attack. Recently much more attention is paid to theapplication of lattice theory in different fields. In this work we propose a latticebased nearest neighbor classifier capable of distinguishing between badconnections, called attacks, and good normal connections. A new nonlinearvaluation function is introduced to tune the performance of the proposed model. Theperformance of the algorithm was evaluated by using KDD Cup 99 Data Set, thebenchmark dataset used by Intrusion detection Systems researchers. Simulationresults confirm the effectiveness of the proposed method.

نویسندگان

Yazdan Jamshidi

Department of Computer Engineering, Science and Research, Islamic Azad University, Kermanshah, Iran

Hossein Nezamabadi-Pour

Department of electrical engineeering, Shahid Bahonar university of Kerman