Implementation of classification and regression Tree (CART) and fuzzy logic algorithm for intrusion detection system

Author(s):  
Asry Faidhul Ashaari Pinem ◽  
Erwin Budi Setiawan
2020 ◽  
Vol 5 (2) ◽  
Author(s):  
Lawrence B Adewole ◽  
Catherine R Adeyeye ◽  
Adebayo O Adetunmbi ◽  
Bosede A Ayogu ◽  
Olaiya Folorunsho

Increase in network traffic coupled with increasing adoption of end-to-end encryption of network packets are two major factors threatening the potency, or even the relevance, of packet-based intrusion detection techniques. Also, end-to-end encryption makes it nearly impossible for network and host-based intrusion detection system to analyze traffic for potential threats and intrusion, hence, the need for an alternative approach. Flow-based intrusion detection system has been proposed as an alternative to a packet-based intrusion detection system as it relies on information embedded in packet header and various statistical analyses of network flow for detecting intrusion.  This paper proposes packet header information abstraction model for intrusion detection on the UNSW-NB15 intrusion dataset. Four existing classification algorithms which include: Classification and Regression Tree (CART), Naïve Bayes (NB), K-Nearest Neighbour (KNN), and Support Vector Machine (SVM) are used to evaluate the degree of representativeness of the proposed model using accuracy, sensitivity and specificity evaluation metrics. An average accuracy of 97.95% was recorded across the four models with the minimum accuracy of 97.76 on SVM and best accuracy of  98.05% on CART while Sensitivity of 1.0 on both CART and NB shows that the model performs well in correctly identifying attacks in the network. The average specificity of 0.98 is also an indication of low false positive.  Results obtained show that the proposed abstraction model achieves high accuracy, sensitivity and specificity. The model can be used as filter on a high-speed network whereby packets flagged as an attack can be subjected to further analysis.Keywords—Data Abstraction, Data Mining,Flow-based, Intrusion detection, Network Security


Author(s):  
V. Chinnasamy ◽  
D. Maruthanayagam

Cloud computing is being heralded as an important trend in information technology throughout the world. Data security has a major issue in cloud computing environment; An intrusion detection system (IDS) is a component that helps to detect various types of malicious network traffic which cannot be detected by a conventional firewall. Many IDS have been developed based on machine learning techniques. In recent growth, advanced detection approaches created by combining or integrating multiple learning techniques have shown better detection performance than general single learning technique. The feature representation method is an important pattern classifier that facilitates correct classifications, however, there have been very few related studies focusing how to extractor representative features for normal connections and effective detection of attacks. The objective of this paper is to suggest new security mechanisms using various trust approaches in broker based federated cloud architecture, ranking the providers with the help of regression tree approach using Service Measurement Index security attributes and new hybrid computation intelligence built on the combination of genetic with Artificial Fish Swarm in Intrusion Detection system.


Sign in / Sign up

Export Citation Format

Share Document