DocumentCode :
1587279
Title :
Multi-layer hybrid machine learning techniques for anomalies detection and classification approach
Author :
Aziz, Amira Sayed A. ; Hassanien, Aboul Ella ; Hanaf, Sanaa El-Ola ; Tolba, M.F.
Author_Institution :
Univ. Francaise d´Egypte (UFE), Cairo, Egypt
fYear :
2013
Firstpage :
215
Lastpage :
220
Abstract :
Intrusion detection systems (IDS) are well-known research area for the detection of anomalous activities in a system from both inside and outside intruders. In this article, a multi-layer hybrid machine learning intrusion detection system is designed and developed to achieve high efficiency and improve the detection and classification rate accuracy inspired by immune systems with negative selection approach. In the first layer, principal component analysis (PCA) algorithm was used for feature selection. Then, genetic algorithm was applied to generate anomaly detectors, which are able to discriminate between normal and anomalous behaviors in the second layer. It is followed by applying classification using several classifiers including naive bayes, multilayer perceptron neural network, and decision trees to increase the detection accuracy and obtain more information on the detected anomalies. The selected classifiers are trained and applied to label the detected anomalies in both the normal and anomalous traffic. The principle interest of this work is to benchmark the performance of the proposed multi-layer IDS system by using NSL-KDD benchmark data set used by IDS researchers. The obtained results demonstrated that naive bayes classifier has better classification accuracy in the case of lower presented attacks such as U2R and R2L, while the J48 decision tree classifier gives high accuracy up to 82% for DoS attacks and 65.4% for probe attacks in the anomaly traffic.
Keywords :
Bayes methods; computer network security; decision trees; feature selection; genetic algorithms; learning (artificial intelligence); pattern classification; principal component analysis; telecommunication traffic; DoS attacks; IDS; J48 decision tree classifier; NSL-KDD benchmark data set; PCA algorithm; R2L; U2R; anomalies detection; anomalous traffic; anomaly detectors; classification approach; feature selection; genetic algorithm; immune systems; multilayer hybrid machine learning intrusion detection system; multilayer perceptron neural network; naive Bayes classifier; negative selection approach; normal traffic; principal component analysis algorithm; probe attacks; Niobium; Probes; Artificial Immune System; Intrusion Classification; Machine Learning; Network Intrusion Detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Hybrid Intelligent Systems (HIS), 2013 13th International Conference on
Conference_Location :
Gammarth
Print_ISBN :
978-1-4799-2438-7
Type :
conf
DOI :
10.1109/HIS.2013.6920485
Filename :
6920485
Link To Document :
بازگشت