Network Anomaly Detection Using Genetic Programming with Semantic Approximation Techniques
Thi Huong Chu, Quang Uy Nguyen · 2021
Network anomaly detection aims at detecting malicious behaviors to the network systems. This problem is of great importance in developing intrusion detection systems to protect networks from intrusive activities. Recently, machine learning-based methods for anomaly detection have become more popular in the research community thanks to their capability in discovering unknown attacks. In the paper, we propose an application of Genetic Programming (GP) with the semantics approximation technique to network anomaly detection. Specifically, two recently proposed techniques for reducing GP code bloat, i.e. Subtree Approximation (SA) and Desired Approximation (DA) are applied for detecting network anomalies. SA and DA are evaluated on 6 datasets in the field of anomaly detection and compared with standard GP and five common machine learning methods. Experimental results show that SA and DA have achieved better results than that of standard GP and the performance of GP is competitive with other machine learning algorithms.