Intrusion detection system framework based on combination of ANN and evidence theory
Chai Qiao-lin · Jisuanji gongcheng yu sheji · 2005
InformationfusionisintroducedandanewIDSframeworkbasedonthecombinationofANNandevidencetheoryisproposed. The new framework is to solve the existing problem that ANN based IDS can't easily acquire enough abundant samples. The neural module of this frameworkconsistsof two parts: Self-organizingmaps (SOM) network and error back propagation (BP) network. The output of the BP network is apiece of evidence, which is the input of evidence theory module. Through information fusion of the evidence theory module, false positives are decreased and the detection rate is improved.