Applying soft computing techniques to intrusion detection

Jugal Kumar Kalita, Lori L. DeLooze · 2005

As more computers are integrated into the Internet, the threat of computer crimes increases and it becomes much more difficult and challenging to predict and prevent computer attacks and malicious intrusions. We apply the soft computing techniques of artificial neural networks, evolutionary computing and fuzzy logic to produce an effective Intrusion Detection System (IDS) to classify attacks by type and characterize the connection according to its behavior. We created an ensemble of Self-Organizing Maps (SOM), one for each of the four major attack families: Denial of Service, Probe, Remote to Local and User to Root. A genetic algorithm determined the best possible feature set for the input vectors of the SOMs. After labeling the attack neurons in the SOM, we formed a fuzzy buffer zone around them. The ensemble of SOMs detected attacks as well or better than any system in the original Knowledge and Data Discovery 1999 Competition. The buffer zone that surrounds the attack nodes can be used for two purposes. First, the nodes in the neighbourhood of the attack nodes characterize the associated connections as either attack-like normal connections or normal-like attack connections. Each connection will have a value from 0 to 1 for each SOM in the collection. This additional information is very valuable to an analyst when considering a wide range of responsive actions. Second, removing the buffer zone from the SOM can amplify the contrast between attacks and other connections. The weights from the nodes remaining after the buffer zone is removed can be used to create a reduced rule set that describes the classification of an attack of that type. We have found that the reduced rules can classify attacks as well as or better than the SOM from which they were derived, with a significantly lower false alarm rate.

Read the paper · More papers on PaperTik