Efficiency of Svm and Pca to Enhance Intrusion Detection System

نویسنده

  • Soukaena Hassan Hashem
چکیده

Intrusion detection system (IDS) is a system that gathers and analyzes information from various areas within a computer or a network to identify attacks made against these components. This research proposed an Intrusion Detection Model (IDM) for detection intrusion attempts, the proposal is a hybrid IDM because it considers both features of network packets and host features that are sensitive to most intrusions. The dataset used to build the hybrid IDM is the proposed HybD (Hybrid Dataset) dataset which composed of the 10% KDD '99 dataset features (41) and suggested host-based features (3). Two Data Mining DM classifiers (Support Vector Machine (SVM)) classifier and Naïve Bayesian (NB) Classifier) are used to build and verify the validity of the proposed model in term of accuracy rate. The proposal trying to ensure the detection speed of the hybrid IDM, that by reducing the HybD dataset features used by considering the most critical features in the detection but with saving of high accuracy rate without degradation that may be caused by that reduction. Two different measures are used for selecting and ranking HybD dataset features; they are Principle Component Analysis (PCA) and Gain Ratio (GR). The sets of feat ures that have been resulted from these two measures and the all features set will be the feeding of both SVM and NB. The results obtained from executing the proposed model showing that SVM classifier accuracy rate is generally higher than that of NB classifier with the three sets of features. With SVM classifier the best accuracy rate resulted with set of features selected by PCA. The most critical features obtained by PCA are ranging to (17) features from 44 features: three of the suggested host features and (14) of the 10% KDD'99 features.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Anomaly Detection Using SVM as Classifier and Decision Tree for Optimizing Feature Vectors

Abstract- With the advancement and development of computer network technologies, the way for intruders has become smoother; therefore, to detect threats and attacks, the importance of intrusion detection systems (IDS) as one of the key elements of security is increasing. One of the challenges of intrusion detection systems is managing of the large amount of network traffic features. Removing un...

متن کامل

A hybridization of evolutionary fuzzy systems and ant Colony optimization for intrusion detection

A hybrid approach for intrusion detection in computer networks is presented in this paper. The proposed approach combines an evolutionary-based fuzzy system with an Ant Colony Optimization procedure to generate high-quality fuzzy-classification rules. We applied our hybrid learning approach to network security and validated it using the DARPA KDD-Cup99 benchmark data set. The results indicate t...

متن کامل

Network Intrusion detection by using PCA via SMO-SVM

As network attacks have increased in number and severity over the past few years, intrusion detection system (IDS) is increasingly becoming a critical component to secure the network. Due to large volumes of security audit data as well as complex and dynamic properties of intrusion behaviors, optimizing performance of IDS becomes an important open problem that is receiving more and more attenti...

متن کامل

Improving Accuracy of Intrusion Detection Model Using PCA and optimized SVM

Extended version of the paper “Intrusion Detection Model Using Fusion of PCA and Optimized SVM” previously presented at International Conference on Computing and Informatics (IC3I), held on November 27–29, 2014, in Mysore, India. Intrusion detection is very essential for providing security to different network domains and is mostly used for locating and tracing the intruders. There are many pro...

متن کامل

Intrusion Detection based on a Novel Hybrid Learning Approach

Information security and Intrusion Detection System (IDS) plays a critical role in the Internet. IDS is an essential tool for detecting different kinds of attacks in a network and maintaining data integrity, confidentiality and system availability against possible threats. In this paper, a hybrid approach towards achieving high performance is proposed. In fact, the important goal of this paper ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013