arrow
返回

Multi-stage intrusion detection system aided by grey wolf optimization algorithm

delete2023-11-10
delete3
delete
OA
AI
S
Somnath Chatterjee *
V
Vaibhav Shaw
R
Ranit Das
DOI:10.1007/s10586-023-04179-4delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
A Network Intrusion Detection System (NIDS) is frequently used for monitoring and detecting malicious activities in network traffic. A typical NIDS has four stages: a data source, data pre-processing, a decision-making technique, and a defense reaction. We have utilized both anomaly and signature based techniques to build a framework which is resilient to identifying both known and unknown attack. The incoming data packet is fed into the Stacked Autoencoder to identify whether it is a benign or malicious. If found to be malicious we extract the most relevant features from the network packet using grey wolf optimization algorithm. Then these attribute are provided to RandomForest classifier to determine if this malign attack is present in our knowledge base. If it is present we progress to identify the attack type using LightGBM classifier. If not, we term it as zero-day attack. To evaluate the usability of the proposed framework we have assessed it using two publicly available datasets namely UNSW-NB15 and CIC-IDS-2017 dataset. We have obtained an accuracy of 90.94% and 99.67% on the datasets respectively.
Keyword:
Computer networks
Intrusion detection system
Stacked autoencoder
Decison trees

期刊

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
论文数:
5.1K
被引数:
7.5K

机构

暂无机构信息
引用论文

引用论文