Intrusion detection using rough set classification.

نویسندگان

  • Lian-hua Zhang
  • Guan-hua Zhang
  • Jie Zhang
  • Ying-cai Bai
چکیده

Recently machine learning-based intrusion detection approaches have been subjected to extensive researches because they can detect both misuse and anomaly. In this paper, rough set classification (RSC), a modern learning algorithm, is used to rank the features extracted for detecting intrusions and generate intrusion detection models. Feature ranking is a very critical step when building the model. RSC performs feature ranking before generating rules, and converts the feature ranking to minimal hitting set problem addressed by using genetic algorithm (GA). This is done in classical approaches using Support Vector Machine (SVM) by executing many iterations, each of which removes one useless feature. Compared with those methods, our method can avoid many iterations. In addition, a hybrid genetic algorithm is proposed to increase the convergence speed and decrease the training time of RSC. The models generated by RSC take the form of "IF-THEN" rules, which have the advantage of explication. Tests and comparison of RSC with SVM on DARPA benchmark data showed that for Probe and DoS attacks both RSC and SVM yielded highly accurate results (greater than 99% accuracy on testing set).

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Intrusion Detection Method Using Protocol Classification and Rough

In order to improve the efficiency of support vector intrusion detection, we first do protocol Classification for the intrusion data, then refine its characteristic by rough set reduction. By using these procedures, we propose an intrusion detection method using protocol classification and rough set based support vector machine. The method is divided into training and testing processes. In the ...

متن کامل

A hybridization of evolutionary fuzzy systems and ant Colony optimization for intrusion detection

A hybrid approach for intrusion detection in computer networks is presented in this paper. The proposed approach combines an evolutionary-based fuzzy system with an Ant Colony Optimization procedure to generate high-quality fuzzy-classification rules. We applied our hybrid learning approach to network security and validated it using the DARPA KDD-Cup99 benchmark data set. The results indicate t...

متن کامل

Feature Selection and Classification of Intrusion Detection System Using Rough Set

With the expansion of computer network there is a challenge to compete with the intruders who can easily break into the system. So it becomes a necessity to device systems or algorithms that can not only detect intrusion but can also improve the detection rate. In this paper we propose an intrusion detection system that uses rough set theory for feature selection, which is extraction of relevan...

متن کامل

Dimensionality Reduction Using Rough Set Approach for Two Neural Networks-Based Applications

In this paper, Rough Sets approach has been used to reduce the number of inputs for two neural networks-based applications that are, diagnosing plant diseases and intrusion detection. After the reduction process, and as a result of decreasing the complexity of the classifiers, the results obtained using Multi-Layer Perceptron (MLP) revealed a great deal of classification accuracy without affect...

متن کامل

A Rough Set based Feature Selection Algorithm for Effective Intrusion Detection in Cloud Model

There exist many problems in intrusion detection systems such as large data volume, features and data redundancy which seriously affect the efficiency of the detection algorithm. Such problems need to be addressed in developing reliable intrusion detection systems. In this paper, we propose an intrusion detection model that combines Rough Set based Feature Selection Algorithm and Fuzzy SVM for ...

متن کامل

A Hybrid Machine Learning Method for Intrusion Detection

Data security is an important area of concern for every computer system owner. An intrusion detection system is a device or software application that monitors a network or systems for malicious activity or policy violations. Already various techniques of artificial intelligence have been used for intrusion detection. The main challenge in this area is the running speed of the available implemen...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Journal of Zhejiang University. Science

دوره 5 9  شماره 

صفحات  -

تاریخ انتشار 2004