RT-UNNID: A practical solution to real-time network-based intrusion detection using unsupervised neural networks

被引:61
作者
Amini, Morteza [1 ]
Jalili, Rasool [1 ]
Shahriari, Hamid Reza [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran, Iran
关键词
network security; intrusion detection systems; misuse detection; anomaly detection; unsupervised neural network; self-organizing map; adaptive resonance theory;
D O I
10.1016/j.cose.2006.05.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the growing rate of network attacks, intelligent methods for detecting new attacks have attracted increasing interest. The RT-UNNID system, introduced in this paper, is one such system, capable of intelligent real-time intrusion detection using unsupervised neural networks. Unsupervised neural nets can improve their analysis of new data over time without retraining. In previous work, we evaluated Adaptive Resonance Theory (ART) and Self-Organizing Map (SOM) neural networks using offline data. in this paper, we present a real-time solution using unsupervised neural nets to detect known and new attacks in network traffic. We evaluated our approach using 27 types of attack, and observed 97% precision using ART nets, and 95% precision using SOM nets. (C) 2006 Elsevier Ltd. All rights reserved.
引用
收藏
页码:459 / 468
页数:10
相关论文
共 32 条
[1]  
AMINI M, 2004, P 4 C ENG INT EIS 20
[2]  
Bishop M., 2003, Computer security: art and science
[3]  
BIVENS A, 2002, P ANNIE, V12
[4]  
Bonifacio JM, 1998, IEEE WORLD CONGRESS ON COMPUTATIONAL INTELLIGENCE, P205, DOI 10.1109/IJCNN.1998.682263
[5]  
Cannady J., 1998, P 1998 NAT INF SYST, P443
[6]  
CANNADY J, 2000, P IEEE INNS ENNS INT, V5, P405
[7]  
COOLEN R, 2002, 49 RTO
[8]  
Debar H., 1992, Proceedings. 1992 IEEE Computer Society Symposium on Research in Security and Privacy (Cat. No.92CH3157-5), P240, DOI 10.1109/RISP.1992.213257
[9]  
DEBAR H, 1992, P INT JOINT C NEUR N, V2, P478
[10]  
Fausett L. V., 1993, FUNDAMENTALS NEURAL