• DocumentCode
    2009058
  • Title

    A Multi-expert Classification Framework with Transferable Voting for Intrusion Detection

  • Author

    Tran, Tich Phuoc ; Tsai, Pohsiang ; Jan, Tony

  • Author_Institution
    Fac. of Inf. Technol., Univ. of Technol. Sydney, Sydney, NSW
  • fYear
    2008
  • fDate
    11-13 Dec. 2008
  • Firstpage
    877
  • Lastpage
    882
  • Abstract
    Network security is a critical component for any sized organization. While static defence technologies such as firewalls and anti-virus provide basic protection for computer networks, an intrusion detection system (IDS) can improve overall security by identifying and responding to novel malicious activities. The current existing IDS methods suffer from low accuracy and system robustness. To overcome such limitations, this paper proposes a multi-expert classification framework for detecting different types of network anomalies. Specifically, different types of intrusions will be detected with different strategies, including different attribute selections and learning algorithms. Several voting approaches are also investigated for the purpose of classifier combination. The Knowledge Discovery and Data Mining (KDD-99) dataset is used as a benchmark to compare this method with other existing techniques. Empirical results indicate that the proposed design outperforms other state-of-the-art learning methods in terms of detection cap abilities, misclassification cost and processing overheads.
  • Keywords
    computer networks; learning (artificial intelligence); pattern classification; security of data; telecommunication computing; telecommunication security; attribute selection; computer network security; intrusion detection system; learning algorithm; malicious activity identification; multiexpert classification framework; network anomaly detection; static defence technology; transferable voting; Australia; Computer networks; Decision trees; Event detection; Face detection; Intrusion detection; Machine learning; Machine learning algorithms; Protection; Voting; multi-expert classification; network intrusion detection; single transferable voting;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Machine Learning and Applications, 2008. ICMLA '08. Seventh International Conference on
  • Conference_Location
    San Diego, CA
  • Print_ISBN
    978-0-7695-3495-4
  • Type

    conf

  • DOI
    10.1109/ICMLA.2008.18
  • Filename
    4725085