RT-UNNID: A practical solution to real-time network-based intrusion detection using unsupervised neural networks

被引:61
作者
Amini, Morteza [1 ]
Jalili, Rasool [1 ]
Shahriari, Hamid Reza [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran, Iran
关键词
network security; intrusion detection systems; misuse detection; anomaly detection; unsupervised neural network; self-organizing map; adaptive resonance theory;
D O I
10.1016/j.cose.2006.05.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the growing rate of network attacks, intelligent methods for detecting new attacks have attracted increasing interest. The RT-UNNID system, introduced in this paper, is one such system, capable of intelligent real-time intrusion detection using unsupervised neural networks. Unsupervised neural nets can improve their analysis of new data over time without retraining. In previous work, we evaluated Adaptive Resonance Theory (ART) and Self-Organizing Map (SOM) neural networks using offline data. in this paper, we present a real-time solution using unsupervised neural nets to detect known and new attacks in network traffic. We evaluated our approach using 27 types of attack, and observed 97% precision using ART nets, and 95% precision using SOM nets. (C) 2006 Elsevier Ltd. All rights reserved.
引用
收藏
页码:459 / 468
页数:10
相关论文
共 32 条
[11]  
GHOSH AK, 1999, P 8 USENIX SEC S
[12]  
Girardin L, 1999, PROCEEDINGS OF THE WORKSHOP ON INTRUSION DETECTION AND NETWORK MONITORING (ID '99), P19
[13]  
HOGLUND AJ, 2000, P IEEE INNS ENNS INT, V5, P411
[14]  
HOREIS T, 2003, INTRUSION DETECTION
[15]  
JALILI R, 2003, P 5 C INT SYST CIS 2
[16]  
JIRAPUMMIN C, 2002, P ITC CSCC, P928
[17]  
KEVIN LF, 1990, P 13 NAT COMP SEC C, P125
[18]  
Labib K, 2002, NSOM REAL TIME NETWO
[19]  
LI T, 1997, THESIS FLORIDA STATE
[20]   Host-based intrusion detection using self-organizing maps [J].
Lichodzijewski, P ;
Zincir-Heywood, AN ;
Heywood, MI .
PROCEEDING OF THE 2002 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, VOLS 1-3, 2002, :1714-1719