Integrated Conditional Random Fields with the Layered Approach for Intrusion Detection

K. Ranganath, Shaik Shafia · 2012

Both Conditional Random Fields (CRFs) and Layered Approach have some things in common. They can be used for solving two issues of Accuracy and Efficiency. They solely do have certain disadvantages and advantages which almost completely disappear by combining both concepts. Intrusion detection (ID) is a type of security management system for computers and networks. An ID system gathers and analyzes information from various areas within a computer or a network to identify possible security breaches, which include both intrusions (attacks from outside the organization) and misuse (attacks from within the organization).The CRFs can effectively model such relationships among different features of an observation resulting in higher attack detection accuracy. Another advantage of using CRFs is that every element in the sequence is labelled such that the probability of the entire labelling is maximized, i.e., all the features in the observation collectively determine the final labels. Hence, even if some data is missing, the observation sequence can still be labelled with less number of features. A layered model is to reduce computation and the overall time required to detect anomalous events. The time required to detect an intrusive event is significant and can be reduced by eliminating the communication overhead among different layers. To improve the speed of operation of the system. Hence, we implement the LIDS and select a small set of features for every layer rather than using all the 41 features. This results in significant performance improvement during both the training and the testing of the system. This project presents high attack detection accuracy can be achieved by using CRFs and high efficiency by implementing the Layered Approach. Finally, we show that our system is robust and is able to handle noisy data without compromising performance

Read the paper · More papers on PaperTik