Sensor Fusion for Enhancement in Intrusion Detection

Ciza Thomas, Balakrishnan Narayanaswamy · InTech eBooks · 2011

An Intrusion Detection System (IDS) gathers information from a computer or a network, and analyzes this information to identify possible security breaches against the system or the network. An observation of various IDSs available in literature shows distinct preferences for detecting a certain class of attack with improved accuracy, while performing moderately on the other classes. The availability of enormous computing power has made it possible for developing and implementing IDSs of different types on the same network. The integration of the decisions coming from different IDSs has emerged as a technique that could strengthen the final decision. Sensor fusion can be defined as the process of collecting information from multiple and possibly heterogeneous sources and combining them to obtain a more descriptive, intuitive and meaningful result (1). An analysis of the poorly detected attacks reveals the fact that the attacks are characterized by features that do not discriminate themmuch. In this chapter, we prove the distinct advantages of sensor fusion over individual IDSs. All the related work in the field of sensor fusion has been carried out mainly with one of the methods like probability theory, evidence theory, voting fusion theory, fuzzy logic theory or neural network in order to aggregate information. The Bayesian theory is the classical method for statistical inference problems. The fusion rule is expressed for a system of independent learners, with the distribution of hypotheses known a priori. The Dempster-Shafer evidence theory is considered a generalized Bayesian theory. It does not require a priori knowledge or probability distribution on the possible system states like the Bayesian approach and it is mostly useful when modeling of the system is difficult or impossible (2). The improved performance of multiple IDSs using rule-based fusion and deta-dependent decision fusion has been demonstrated in the work of Thomas and Balakrishnan (3). An attempt to prove the distinct advantages of sensor fusion over individual IDSs is done in this chapter using the Chebyshev inequality. Fusion threshold bounds were derived using the principle of Chebyshev inequality at the fusion center using the false positive rates and detection rates of the IDSs. The goal was to achieve best fusion performance with the least amount of model knowledge, in a computationally inexpensive way. The anomaly-based IDSs detect anomalies beyond a set threshold level in the features it detects. Threshold bounds instead of a single threshold give more freedom in steering system properties. Any threshold 4

Read the paper · More papers on PaperTik