Adaptive Anomaly-Based Intrusion Detection System Using Fuzzy Controller.
Farzaneh Geramiraz, Amir Saman Memaripour, Maghsoud Abbaspour · International journal of network security · 2012
The main feature of anomaly-based intrusion detection systems is detection of new attacks in the networks, even though numerous false alarms are caused in order to disregard this important feature. Although the previous improved detection models decrease the number of false alarms, but their efficiency due to changes in the normal behavior of the system is not reasonable. In this paper, we present an anomaly-based intrusion detection system to improve the system performance. Fuzzy rule-based modeling and fuzzy controller are used to create a detection model in the training phase and update this model in the test phase respectively. Moreover, the results of system’s predictions buffered and presented to the system user later. After that, system user verifies these decisions and fuzzy controller tunes detection model using system user’s feedbacks. We evaluated our system using the NCL dataset. Our dataset is a subset of KDD-99 dataset that does not contain any duplicated record. Furthermore, it includes a few difficult records that none of common classification methods in this area is able to classify them correctly. We have also proved that our test results can significantly increase the performance of the system about 20 percent using adaptive IDS. We also conclude that our proposed anomaly based intrusion detection increases the accuracy of the system about 15 percent.