Evolving Fuzzy Classifiers for Intrusion Detection
Jonatan Gómez, Dipankar Dasgupta · 2002
The normal and the abnormal behaviors in networked computers are hard to predict as the boundaries cannot be well defined. This prediction process may generate false alarms in many anomaly based intrusion detection systems. However, with fuzzy logic, the false alarm rate in determining intrusive activities can be reduced; a set of fuzzy rules (non-crisp fuzzy classifiers) can be used to define the normal and abnormal behavior in a computer network, and a fuzzy inference algorithm can be applied over such rules to determine when an intrusion is in progress. The main problem with this approach is to generate good fuzzy classifiers to detect intrusions. This paper proposes a technique to generate fuzzy classifiers using genetic algorithms that can detect anomalies and some specific intrusions. The main idea is to evolve two rules, one for the normal class and other for the abnormal class using a profile data set (a preprocessed DARPA data set is used (1)) with information related to the computer network during the normal behavior and during intrusive (abnormal) behavior. This paper exhibits some results and reports the performance of evolved fuzzy classifiers in intrusion detection.