Development of an Evolutionary Framework for Autonomous Rule Creation for Intrusion Detection
Sunitha Guruprasad, Rio G. L. D’Souza · 2016
Network intrusion detection system (IDS) plays a major role in any security based architecture. Various IDS have been developed to detect the intrusions that occur in the real world. The most commonly used network security tool used is Snort IDS. Snort is a rule-based system that generates alerts for the matching network patterns. Most of the rules stored in the Snort database fail to generate alerts for real network traffic. It is necessary to create rules that detect the attacks efficiently. In this paper we have made an attempt to autonomously generate rules using the evolutionary approach. The rules produced were tested for Darpa 1999, ISCX 2012 and ICMP network packets and were able to detect attacks with a high detection rate.