A Lattice based Nearest Neighbor Classifier for Anomaly Intrusion Detection

  • سال انتشار: 1392
  • محل انتشار: مجله پیشرفت در تحقیقات کامپیوتری، دوره: 4، شماره: 4
  • کد COI اختصاصی: JR_JACR-4-4_005
  • زبان مقاله: انگلیسی
  • تعداد مشاهده: 490
دانلود فایل این مقاله

نویسندگان

Yazdan Jamshidi

Department of Computer Engineering, Science and Research, Islamic Azad University, Kermanshah, Iran

Hossein Nezamabadi-Pour

Department of electrical engineeering, Shahid Bahonar university of Kerman

چکیده

As networking and communication technology becomes more widespread, thequantity and impact of system attackers have been increased rapidly. Themethodology of intrusion detection (IDS) is generally classified into two broadcategories according to the detection approaches: misuse detection and anomalydetection. In misuse detection approach, abnormal system behavior is defined atfirst, and then any other behavior is defined as normal behavior. The main goal ofthe anomaly detection approach is to construct a model representing normalactivities. Then, any deviation from this model can be considered as an anomaly,and recognized to be an attack. Recently much more attention is paid to theapplication of lattice theory in different fields. In this work we propose a latticebased nearest neighbor classifier capable of distinguishing between badconnections, called attacks, and good normal connections. A new nonlinearvaluation function is introduced to tune the performance of the proposed model. Theperformance of the algorithm was evaluated by using KDD Cup 99 Data Set, thebenchmark dataset used by Intrusion detection Systems researchers. Simulationresults confirm the effectiveness of the proposed method.

کلیدواژه ها

Anomaly detection, Nearest Neighbor, Lattice Theory, Positive Valuation Function, KDD Cup 99

مقالات مرتبط جدید

اطلاعات بیشتر در مورد COI

COI مخفف عبارت CIVILICA Object Identifier به معنی شناسه سیویلیکا برای اسناد است. COI کدی است که مطابق محل انتشار، به مقالات کنفرانسها و ژورنالهای داخل کشور به هنگام نمایه سازی بر روی پایگاه استنادی سیویلیکا اختصاص می یابد.

کد COI به مفهوم کد ملی اسناد نمایه شده در سیویلیکا است و کدی یکتا و ثابت است و به همین دلیل همواره قابلیت استناد و پیگیری دارد.