Real-Time Anomaly Detection Without False Positives Using Genetic Algorithm

Swati Anand, Bansod Malvika Prabodh, N. A. S. Vinoth · 2024

This research work addresses the growing significance of Anomaly Detection Systems (IDSs) in ensuring the security of digital systems and networks. The inherent challenge in distinguishing genuine anomalies from benign variations in network traffic demands considerable time and effort from analysts. To address this issue, the study proposes a novel approach that integrates Genetic Algorithm (GA) with machine learning and data mining technologies for real-time anomaly detection with a focus on minimizing false positives. The methodology involves using the genetic algorithm to evolve decision tree-based rules that encapsulate the characteristics of anomalies, enabling the system to autonomously discern between normal and aberrant behavior. By incorporating these rules into the genetic algorithm, the system gains the capability to proactively prevent identified anomalies, going beyond mere detection to actively mitigate potential threats. The research methodology includes creating a diverse dataset representative of network activities and anomalies, iteratively refining decision tree rules through the genetic algorithm, and evaluating the resulting model in real-time scenarios. The innovative amalgamation of genetic algorithms with decision tree-based classification offers a promising avenue for enhancing the efficiency and reliability of IDSs, with potential implications for the broader field of cybersecurity by providing a proactive defense mechanism against network anomalies and fortifying the resilience of digital infrastructures.

Read the paper · More papers on PaperTik