arrow
Return

A Pareto-based multi-objective evolutionary algorithm for automatic rule generation in network intrusion detection systems

delete2012-07-13
delete31
PRE
AI
J
Julio Gómez *
C
C. Gil
R
Raúl Baños
A
A. L. Márquez
F
Francisco G. Montoya
M
Montoya, M. G.
DOI:10.1007/s00500-012-0890-9delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Attacks against computer systems are becoming more complex, making it necessary to continually improve the security systems, such as intrusion detection systems which provide security for computer systems by distinguishing between hostile and non-hostile activity. Intrusion detection systems are usually classified into two main categories according to whether they are based on misuse (signature-based) detection or on anomaly detection. With the aim of minimizing the number of wrong decisions, a new Pareto-based multi-objective evolutionary algorithm is used to optimize the automatic rule generation of a signature-based intrusion detection system (IDS). This optimizer, included within a network IDS, has been evaluated using a benchmark dataset and real traffic of a Spanish university. The results obtained in this real application show the advantages of using this multi-objective approach.
Keywords:
Computer security
Network intrusion detection system
Signature detection
Evolutionary multi-objective optimization

Journal

Soft Computing cover
Soft Computing
IF:
2.5
Papers:
1.0W
Citations:
2.1W

Organization

U
universidad de almeria
Scholars:
4.4K
Papers: 4.0K
Citations: 1
U
University of Granada
Scholars:
2.3W
Papers: 1.9W
Citations: 24