TL-IDPS: Two Level Intrusion Detection and Prevention System using Probabilistic Optimal Feature Set Estimation

Ernest Ntizikira, Lei Wang, Bingxian Lu, Xinxin Lu · 2020

Wireless networks that can exchange any type of data are vulnerable to multiple intrusions and increase potential security risks, so the design of an Intrusion Detection and Prevention System (IDPS) that analyzes the packet features and detects different intruders (i.e., the types of attack) is necessary. Whereas, the existence of redundant and irrelevant features hinders the potential of IDPS. In this paper, we propose TL-IDPS, a Two-Level classification IDPS of wireless network based on optimized features. In the phase of intrusion detection, one-hot method, normalization and correlation estimation are used to mitigate the redundant features. Then, the fuzzy membership function with cuttlefish algorithm maps and consolidates the extracted features and selects optimal features. Based on the optimal features, Di-distance k-nearest neighbor (K-NN) as the first level classify the intruder or non-intruder. Further the type of intruder is identified by deep Q-network. From the result of detected intruders, the further arrival of those intruders is prevented. Experimental results conducted from multiple evaluation metrics using the UNSW-NB15 dataset prove that our proposed TL-IDPS is more effective than existing IDPS methods.

Read the paper · More papers on PaperTik