Hybrid Intrusion Detection System for Detecting New Attacks Using Machine Learning
V. S. Felix Enigo, Kumar T Ganesh, Nitish Raj, D. Sandeep · 2020
Traditional Intrusion Detection Systems are used to detect malicious activities, policy violations, and produce relevant alerts. But most of the commercially available Intrusion Detection Systems are not capable of detecting newer attacks. Also, these intrusion detection systems produce a lot of alerts for a single complex attack. In this paper, an attempt is done to build a real-time hybrid intrusion detection system, which could be helpful to detect newer attacks as well as group together alerts of a complex attack for better Incident Response. The newer attacks are identified from the model built from the KDD dataset using various supervised machine learning algorithms. The complex attacks are clustered in the alert correlation module using DBScan density-based clustering algorithm. The model identifies a similar attack encountered in the future resulting in a greatly improved incident response.