Intrusion detection using rough set classification

作者: Lian-hua Zhang , Guan-hua Zhang , Lang Yu , Jie Zhang , Ying-cai Bai

DOI: 10.1631/JZUS.2004.1076

关键词:

摘要: Recently machine learning-based intrusion detection approaches have been subjected to extensive researches because they can detect both misuse and anomaly. In this paper, rough set classification (RSC), a modern learning algorithm, is used rank the features extracted for detecting intrusions generate models. Feature ranking very critical step when building model. RSC performs feature before generating rules, converts minimal hitting problem addressed by using genetic algorithm (GA). This done in classical Support Vector Machine (SVM) executing many iterations, each of which removes one useless feature. Compared with those methods, our method avoid iterations. addition, hybrid proposed increase convergence speed decrease training time RSC. The models generated take form “IF-THEN” advantage explication. Tests comparison SVM on DARPA benchmark data showed that Probe DoS attacks yielded highly accurate results (greater than 99% accuracy testing set).

参考文章(8)
Julia Allen, Alan Christie, William Fithen, John McHugh, Jed Pickel, State of the Practice of Intrusion Detection Technologies Defense Technical Information Center. ,(2000) , 10.21236/ADA375846
Anders Torvill Bjorvand, “Rough enough”—a system supporting the rough sets approach scandinavian conference on ai. pp. 290- 291 ,(1998)
Jan G. Bazan, Andrzej Skowron, Piotr Synak, Dynamic Reducts as a Tool for Extracting Laws from Decisions Tables international syposium on methodologies for intelligent systems. pp. 346- 355 ,(1994) , 10.1007/3-540-58495-1_35
Wenke Lee, Salvatore J. Stolfo, A framework for constructing features and models for intrusion detection systems ACM Transactions on Information and System Security. ,vol. 3, pp. 227- 261 ,(2000) , 10.1145/382912.382914
Chih-Chung Chang, Chih-Jen Lin, LIBSVM ACM Transactions on Intelligent Systems and Technology. ,vol. 2, pp. 1- 27 ,(2011) , 10.1145/1961189.1961199
Zdzisław Pawlak, Rough sets Communications of the ACM. ,vol. 38, pp. 88- 95 ,(1995) , 10.1145/219717.219791