CIVILICA We Respect the Science
(ناشر تخصصی کنفرانسهای کشور / شماره مجوز انتشارات از وزارت فرهنگ و ارشاد اسلامی: ۸۹۷۱)

A Lattice based Nearest Neighbor Classifier for Anomaly Intrusion Detection

عنوان مقاله: A Lattice based Nearest Neighbor Classifier for Anomaly Intrusion Detection
شناسه ملی مقاله: JR_JACR-4-4_005
منتشر شده در شماره 4 دوره 4 فصل Autumn در سال 1392
مشخصات نویسندگان مقاله:

Yazdan Jamshidi - Department of Computer Engineering, Science and Research, Islamic Azad University, Kermanshah, Iran
Hossein Nezamabadi-Pour - Department of electrical engineeering, Shahid Bahonar university of Kerman

خلاصه مقاله:
As networking and communication technology becomes more widespread, thequantity and impact of system attackers have been increased rapidly. Themethodology of intrusion detection (IDS) is generally classified into two broadcategories according to the detection approaches: misuse detection and anomalydetection. In misuse detection approach, abnormal system behavior is defined atfirst, and then any other behavior is defined as normal behavior. The main goal ofthe anomaly detection approach is to construct a model representing normalactivities. Then, any deviation from this model can be considered as an anomaly,and recognized to be an attack. Recently much more attention is paid to theapplication of lattice theory in different fields. In this work we propose a latticebased nearest neighbor classifier capable of distinguishing between badconnections, called attacks, and good normal connections. A new nonlinearvaluation function is introduced to tune the performance of the proposed model. Theperformance of the algorithm was evaluated by using KDD Cup 99 Data Set, thebenchmark dataset used by Intrusion detection Systems researchers. Simulationresults confirm the effectiveness of the proposed method.

کلمات کلیدی:
Anomaly detection, Nearest Neighbor, Lattice Theory, Positive Valuation Function, KDD Cup 99

صفحه اختصاصی مقاله و دریافت فایل کامل: https://civilica.com/doc/488414/