Intrusion detection system using hybrid GSA-k-Means

Security is an important aspect in our daily life. Intrusion Detection Systems (IDS) are developed to be the defense against security threats. Current signature based IDS like firewalls and antiviruses, which rely on labeled training data, generally cannot detect novel attacks. The purpose of this s...

詳細記述

書誌詳細
第一著者: Aslahi, Bibi Masoomeh
フォーマット: 学位論文
言語:英語
出版事項: 2013
主題:
オンライン・アクセス:http://eprints.utm.my/78118/1/BibiMasoomehAslahiMFC20131.pdf
_version_ 1846217846275702784
author Aslahi, Bibi Masoomeh
author_facet Aslahi, Bibi Masoomeh
author_sort Aslahi, Bibi Masoomeh
description Security is an important aspect in our daily life. Intrusion Detection Systems (IDS) are developed to be the defense against security threats. Current signature based IDS like firewalls and antiviruses, which rely on labeled training data, generally cannot detect novel attacks. The purpose of this study is to improve the performance of IDS in terms of detection accuracy and reduce False Alarm Rate (FAR). Clustering is an important task in data mining that is used in IDS applications to detect novel attacks. Clustering refers to grouping together data objects so that objects within a cluster are similar to one another, while objects in different clusters are dissimilar. K-Means is a simple and efficient algorithm that is widely used for data clustering. However, its performance depends on the initial state of centroids and may trap in local optima. The Gravitational Search Algorithm (GSA) is one effective method for searching problem space to find a near optimal solution. In this study, a hybrid approach based on GSA and k-Means (GSA-kMeans), which uses the advantages of both algorithms, is presented. The performance of GSA-kMeans is compared with other well-known algorithms, including k-Means and Gravitational Search Algorithm (GSA). Experimental results on the KDDCup 1999 dataset have demonstrated that the proposed method is more efficient in the detection of intrusive behavior than conventional k-Means and standard GSA which shows 80.62% detection accuracy and 7.45% FAR.
format Thesis
id uthm-78118
institution Universiti Teknologi Malaysia
language English
publishDate 2013
record_format eprints
spelling uthm-781182018-07-25T08:17:37Z http://eprints.utm.my/78118/ Intrusion detection system using hybrid GSA-k-Means Aslahi, Bibi Masoomeh QA75 Electronic computers. Computer science Security is an important aspect in our daily life. Intrusion Detection Systems (IDS) are developed to be the defense against security threats. Current signature based IDS like firewalls and antiviruses, which rely on labeled training data, generally cannot detect novel attacks. The purpose of this study is to improve the performance of IDS in terms of detection accuracy and reduce False Alarm Rate (FAR). Clustering is an important task in data mining that is used in IDS applications to detect novel attacks. Clustering refers to grouping together data objects so that objects within a cluster are similar to one another, while objects in different clusters are dissimilar. K-Means is a simple and efficient algorithm that is widely used for data clustering. However, its performance depends on the initial state of centroids and may trap in local optima. The Gravitational Search Algorithm (GSA) is one effective method for searching problem space to find a near optimal solution. In this study, a hybrid approach based on GSA and k-Means (GSA-kMeans), which uses the advantages of both algorithms, is presented. The performance of GSA-kMeans is compared with other well-known algorithms, including k-Means and Gravitational Search Algorithm (GSA). Experimental results on the KDDCup 1999 dataset have demonstrated that the proposed method is more efficient in the detection of intrusive behavior than conventional k-Means and standard GSA which shows 80.62% detection accuracy and 7.45% FAR. 2013-01 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/78118/1/BibiMasoomehAslahiMFC20131.pdf Aslahi, Bibi Masoomeh (2013) Intrusion detection system using hybrid GSA-k-Means. Masters thesis, Universiti Teknologi Malaysia, Faculty of Computing. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:82652
spellingShingle QA75 Electronic computers. Computer science
Aslahi, Bibi Masoomeh
Intrusion detection system using hybrid GSA-k-Means
title Intrusion detection system using hybrid GSA-k-Means
title_full Intrusion detection system using hybrid GSA-k-Means
title_fullStr Intrusion detection system using hybrid GSA-k-Means
title_full_unstemmed Intrusion detection system using hybrid GSA-k-Means
title_short Intrusion detection system using hybrid GSA-k-Means
title_sort intrusion detection system using hybrid gsa k means
topic QA75 Electronic computers. Computer science
url http://eprints.utm.my/78118/1/BibiMasoomehAslahiMFC20131.pdf
url-record http://eprints.utm.my/78118/
http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:82652
work_keys_str_mv AT aslahibibimasoomeh intrusiondetectionsystemusinghybridgsakmeans