返回
Evolving statistical rulesets for network intrusion detection
DOI:10.1016/j.asoc.2015.04.041.png)
摘要
En 中文
Security threats against computer networks and the Internet have emerged as a major and increasing area of concern for end-users trying to protect their valuable information and resources from intrusive attacks. Due to the amount of data to be analysed and the similarities between attack and normal traffic patterns, intrusion detection is considered a complex real world problem. In this paper, we propose a solution that uses a genetic algorithm to evolve a set of simple, interval-based rules based on statistical, continuous-valued input data. Several innovations in the genetic algorithm work to keep the ruleset small. We first tune the proposed system using a synthetic data. We then evaluate our system against more complex synthetic data with characteristics associated with network intrusions, the NSL-KDD benchmark dataset, and another dataset constructed based on MIT Lincoln Laboratory normal traffic and the low-rate DDoS attack scenario from CAIDA. This new approach provides a very compact set of simple, humanreadable rules with strongly competitive detection performance in comparison to other machine learning techniques. (C) 2015 Elsevier B.V. All rights reserved.
Keyword:
Intrusion detection
DARPA
NSL-KDD
Genetic algorithm
Interval rule-based
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
6.6
论文数:
1.4W
被引数:
4.8W
机构
引用论文
Anomaly-based network intrusion detection: Techniques, systems and challenges
COMPUTERS & SECURITY
IF5.4
Combining boosting and evolutionary algorithms for learning of fuzzy classification rules结合boosting和进化算法学习模糊分类规则

