Title :
A Bio-inspired Host-Based Multi-engine Detection System with Sequential Pattern Recognition
Author :
Jiang, Frank ; Frater, Michael ; Hu, Jiankun
Author_Institution :
Sch. of Eng. & IT, Univ. of New South Wales, Sydney, NSW, Australia
Abstract :
In this paper, multiple detection engines with multi-layered intrusion detection mechanisms are proposed. The principle is to coordinate the results from each single-engine intrusion alert system, by seamlessly integrating with the multiple layered distributed service-oriented structure. An improved hidden Markov model (HMM) is created for the detection engine which is capable of the immunology-based self/nonself discrimination. The classifications of normal and abnormal behaviours of system calls are further examined by an advanced fuzzy-based inference process called HPSOWM. Considering a real benchmark dataset from the public domain, our experimental results show that the proposed scheme can greatly shorten the training time of HMM and reduce the false positive rate significantly. The proposed HPSOWM especially works for the efficient classification of unknown behaviors and malicious attacks.
Keywords :
artificial immune systems; distributed processing; fuzzy reasoning; hidden Markov models; pattern recognition; security of data; service-oriented architecture; HPSOWM; bioinspired host based multiengine detection system; distributed service oriented structure; fuzzy based inference process; hidden Markov model; immunology based nonself discrimination; immunology based self discrimination; malicious attacks; multilayered intrusion detection mechanisms; sequential pattern recognition; single engine intrusion alert system; Computational modeling; Engines; Fuzzy reasoning; Hidden Markov models; Immune system; Testing; Training; Anomaly intrusion detection; Fuzzy logic; Hidden Markov model; Immunology; Multiple detection engines;
Conference_Titel :
Dependable, Autonomic and Secure Computing (DASC), 2011 IEEE Ninth International Conference on
Conference_Location :
Sydney, NSW
Print_ISBN :
978-1-4673-0006-3
DOI :
10.1109/DASC.2011.46