Enhancing effectiveness of intrusion detection systems: A hybrid approach
Basant Subba, Santosh Biswas, Sushanta Karmakar · 2016
Intrusion Detection Systems (IDSs) proposed in the literature can broadly be classified as either signature based or anomaly based. Although both these classes of IDSs effectively detect wide range of network attacks, they have their own set of drawbacks. Signature based IDSs are incapable of detecting new attacks and produce a large number of false positive alarms when operated with default settings. On the other hand, anomaly based IDSs require extensive training before deployment and are computationally expensive. In this paper, we aim to address these issues by proposing an efficient hybrid intrusion detection framework with high detection rate and low false alarm rate. A novel false alarm minimization technique is used to reduce the false alarm rate of the signature based component and a simple header based anomaly detection module is used to minimize the computational overhead of the anomaly based component. Experimental results on the benchmark DARPA IDEVAL dataset and an in-house test bed dataset show that the proposed framework achieves a high detection rate and accuracy across a wide range of network attacks, while at the same time minimizes the overall computational overhead.