Intrusion Detection Based on the Game Theory
Yuqing Cheng, Haiyan Fu, Xuechao Sun · International Conference on Frontiers of Electronics, Information and Computation Technologies · 2021
With the development of computer technology, many new network intrusion and attack technologies have emerged. However, the existing network intrusion detection model has a complicated modeling process, and the kdd99 data set used to verify the model can not reflect the characteristics of current network intrusion attacks. Therefore, the work applied the game theory to the binary classification of intrusion detection and established a game-theory model between the intruder and the intrusion detection system. Both parties adopted the Nash equilibrium strategy to obtain the minimum solution between the intruder and the intrusion detection system and their respective utility functions. Finally, the UNSW_NB test set was used for testing. The test results showed that the game model in the work had fast modeling speed and fast attack detection speed. Except for the two categories of Normal and Exploits, the recall rates of other categories had reached more than 90%. Wherein, the recall rate of the three categories of Backdoor, Analysis, and Worms on the test set reached 100%. Compared with the GA-LR model, the model is effective and feasible in intrusion detection.