Flow-Based Anomaly Intrusion Detection System Using Two Neural Network Stages
Computer Science and Information Systems, Tome 11 (2014) no. 2
Cet article a éte moissonné depuis la source Computer Science and Information Systems website
Computer systems and networks suffer due to rapid increase of attacks, and in order to keep them safe from malicious activities or policy violations, there is need for effective security monitoring systems, such as Intrusion Detection Systems (IDS). Many researchers concentrate their efforts on this area using different approaches to build reliable intrusion detection systems. Flow-based intrusion detection systems are one of these approaches that rely on aggregated flow statistics of network traffic. Their main advantages are host independence and usability on high speed networks, since the metrics may be collected by network device hardware or standalone probes. In this paper, an intrusion detection system using two neural network stages based on flow-data is proposed for detecting and classifying attacks in network traffic. The first stage detects significant changes in the traffic that could be a potential attack, while the second stage defines if there is a known attack and in that case classifies the type of attack. The first stage is crucial for selecting time windows where attacks, known or unknown, are more probable. Two different neural network structures have been used, multilayer and radial basis function networks, with the objective to compare performance, memory consumption and the time required for network training. The experimental results demonstrate that the designed models are promising in terms of accuracy and computational time, with low probability of false alarms.
Keywords:
Intrusion Detection system, Anomaly detection system, Neural Network, NetFlow
@article{CSIS_2014_11_2_a9,
author = {Yousef Abuadlla and Goran Kvascev and Slavko Gajin and Zoran Jovanovic},
title = {Flow-Based {Anomaly} {Intrusion} {Detection} {System} {Using} {Two} {Neural} {Network} {Stages}},
journal = {Computer Science and Information Systems},
year = {2014},
volume = {11},
number = {2},
url = {http://geodesic.mathdoc.fr/item/CSIS_2014_11_2_a9/}
}
TY - JOUR AU - Yousef Abuadlla AU - Goran Kvascev AU - Slavko Gajin AU - Zoran Jovanovic TI - Flow-Based Anomaly Intrusion Detection System Using Two Neural Network Stages JO - Computer Science and Information Systems PY - 2014 VL - 11 IS - 2 UR - http://geodesic.mathdoc.fr/item/CSIS_2014_11_2_a9/ ID - CSIS_2014_11_2_a9 ER -
%0 Journal Article %A Yousef Abuadlla %A Goran Kvascev %A Slavko Gajin %A Zoran Jovanovic %T Flow-Based Anomaly Intrusion Detection System Using Two Neural Network Stages %J Computer Science and Information Systems %D 2014 %V 11 %N 2 %U http://geodesic.mathdoc.fr/item/CSIS_2014_11_2_a9/ %F CSIS_2014_11_2_a9
Yousef Abuadlla; Goran Kvascev; Slavko Gajin; Zoran Jovanovic. Flow-Based Anomaly Intrusion Detection System Using Two Neural Network Stages. Computer Science and Information Systems, Tome 11 (2014) no. 2. http://geodesic.mathdoc.fr/item/CSIS_2014_11_2_a9/