Intrusion detection using a linguistic hedged fuzzy-XCS classifier system

被引:11
作者
Marin-Blazquez, Javier G. [1 ]
Martinez Perez, Gregorio [1 ]
机构
[1] Univ Murcia, Fac Informat, Dept Ingn Informac & Comunicac, E-30071 Murcia, Spain
关键词
Genetic Algorithm; Intrusion Detection; Anomaly Detection; Intrusion Detection System; Security Expert;
D O I
10.1007/s00500-008-0322-z
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intrusion detection systems (IDS) are a fundamental defence component in the architecture of the current telecommunication systems. Misuse detection is one of the different approaches to create IDS. It is based on the automatic generation of detection rules from labelled examples. Such examples are either attacks or normal situations. From this perspective the problem can be viewed as a supervised classification one. In this sense, this paper proposes the use of XCS as a classification technique to aid in the tasks of misuse detection in IDS systems. The final proposed XCS variant includes the use of hedged linguistic fuzzy classifiers to allow for interpretability. The use of this linguistic fuzzy approach provides with both the possibility of testing human designed detectors and a posteriori human fine tuning of the models obtained. To evaluate the performance not only several classic classification problems as Wine or Breast Cancer datasets are considered, but also a problem based on real data, the KDD-99. This latter problem, the KDD-99, is a classic in the literature of intrusion systems. It shows that with simple configurations the proposed variant obtains competitive results compared with other techniques shown in the recent literature. It also generates human interpretable knowledge, something very appreciated by security experts. In fact, this effort is integrated into a global detection architecture, where the security administrator is guiding part of the intrusion detection (and prevention) process.
引用
收藏
页码:273 / 290
页数:18
相关论文
共 38 条
[21]  
LEUNG K, 2005, ACSC, V38
[22]  
Marín-Blázquez JG, 2001, 10TH IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS, VOLS 1-3, P412, DOI 10.1109/FUZZ.2001.1007336
[23]   From approximative to descriptive fuzzy classifiers [J].
Marín-Blázquez, JG ;
Shen, Q .
IEEE TRANSACTIONS ON FUZZY SYSTEMS, 2002, 10 (04) :484-497
[24]  
MARINBLAZQUEZ JG, 2007, MAEB07
[25]  
MARINBLAZQUEZ JG, 2007, FUZZIEEE 2007
[26]  
McHugh J., 2000, ACM Transactions on Information and Systems Security, V3, P262, DOI 10.1145/382912.382923
[27]  
MILLER GA, 1956, PSYCHOL REV, V63, P81, DOI 10.1037/0033-295X.101.2.343
[28]  
Oldmeadow J, 2004, LECT NOTES ARTIF INT, V3056, P255
[29]  
ORRIOLSPUIG A, 2006, GECCO 2006, V2, P1561
[30]  
ORRIOLSPUIG A, 2005, GENETIC EVOLUTIONARY, P74