DocumentCode :
1805199
Title :
Lightweight IDS Based on Features Selection and IDS Classification Scheme
Author :
Zaman, Safaa ; Karray, Fakhri
Author_Institution :
ECE Dept., Univ. of Waterloo, Waterloo, ON, Canada
Volume :
3
fYear :
2009
fDate :
29-31 Aug. 2009
Firstpage :
365
Lastpage :
370
Abstract :
The intrusion detection system (IDS) deals with huge amount of data which contains irrelevant and redundant features causing slow training and testing process, higher resource consumption as well as poor detection rate. To overcome these limitations, we introduce the concept of lightweight IDS. The lightweight IDSs are small, powerful, and flexible enough to be used as permanent elements of the network security infrastructure. In this paper, we propose a novel concept for building lightweight IDS based on two different approaches. The first approach is using a features selection approach by applying fuzzy enhanced support vector decision function (Fuzzy ESVDF) algorithm. This approach is able to improve system efficiency. The second approach is using IDS classification scheme. The IDS classification scheme divides the detection process into four types according to the TCP/IP network model (application layer IDS, transport layer IDS, network layer IDS, and link layer IDS). This IDS classification scheme enhances an organizationpsilas ability to detect most types of attack (improving system accuracy and generality). Also, it improves IDS scalability and extendibility. To design the proposed system, several experiments have been conducted, and they indicate that the proposed lightweight IDS can deliver satisfactory system performance.
Keywords :
computer networks; feature extraction; fuzzy set theory; pattern classification; support vector machines; telecommunication security; transport protocols; TCP/IP network model; application layer IDS; feature selection; fuzzy enhanced support vector decision function algorithm; intrusion detection system; lightweight IDS classification scheme; link layer IDS; network layer IDS; network security; transport layer IDS; Data engineering; Fuzzy sets; IP networks; Information systems; Intrusion detection; Scalability; System performance; System testing; TCPIP; Telecommunication traffic; Intrusion Detection Systems; Support Decision Function; features classification.; features ranking; features selection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Science and Engineering, 2009. CSE '09. International Conference on
Conference_Location :
Vancouver, BC
Print_ISBN :
978-1-4244-5334-4
Electronic_ISBN :
978-0-7695-3823-5
Type :
conf
DOI :
10.1109/CSE.2009.180
Filename :
5283334
Link To Document :
بازگشت