TY - GEN
T1 - A novel adaptive intrusion detection approach based on comparison of neural networks and idiotypic networks
AU - Zhao, Linhui
AU - Fang, Xin
AU - Dai, Yaping
PY - 2009
Y1 - 2009
N2 - Although neural networks and idiotypic networks are similar in functions, they are different in many aspects. This paper compares them in topological structures, initializing ways, learning methods, et al. Based on the comparison and combined with pattern recognition technology, this paper proposes a novel adaptive intrusion detection approach using idiotypic networks. Additionally, the approach is compared with detection approach using neural networks. Idiotypic networks' memory and learning abilities, especially their dynamic adjustable ability enable them superior to neural networks in the application for intrusion detection. This paper presents a new detection algorithm according to immune response principles and a new multimutation pattern idiotypic network model to implement the detection algorithm. By utilizing some immune principles, the proposed approach can overcome problems existing in detection approaches based on neural networks. Firstly, idiotypic networks can adjust automatically with presenting of antigens, making new features fused into networks continuously. Thus, this approach needs not to be updated periodically. Secondly, the trained network model can still be changed to learn new features of attacks, so the performance of detecting unknown attacks is improved. Thirdly, clone expansion of antibodies is suppressed by idiotypic effects, thus false positive rate is decreased. Experiments are carried out on Fisher Iris dataset and KDDCUP-99 database to verify the performance of this adaptive detection approach. Compared with the detection approach based on a multilayer perception network, the false positive rate is decreased and the detection accuracy of unknown attacks is increased.
AB - Although neural networks and idiotypic networks are similar in functions, they are different in many aspects. This paper compares them in topological structures, initializing ways, learning methods, et al. Based on the comparison and combined with pattern recognition technology, this paper proposes a novel adaptive intrusion detection approach using idiotypic networks. Additionally, the approach is compared with detection approach using neural networks. Idiotypic networks' memory and learning abilities, especially their dynamic adjustable ability enable them superior to neural networks in the application for intrusion detection. This paper presents a new detection algorithm according to immune response principles and a new multimutation pattern idiotypic network model to implement the detection algorithm. By utilizing some immune principles, the proposed approach can overcome problems existing in detection approaches based on neural networks. Firstly, idiotypic networks can adjust automatically with presenting of antigens, making new features fused into networks continuously. Thus, this approach needs not to be updated periodically. Secondly, the trained network model can still be changed to learn new features of attacks, so the performance of detecting unknown attacks is improved. Thirdly, clone expansion of antibodies is suppressed by idiotypic effects, thus false positive rate is decreased. Experiments are carried out on Fisher Iris dataset and KDDCUP-99 database to verify the performance of this adaptive detection approach. Compared with the detection approach based on a multilayer perception network, the false positive rate is decreased and the detection accuracy of unknown attacks is increased.
KW - Idiotypic networks
KW - Intrusion detection
KW - Neural networks
KW - Pattern recognition
UR - http://www.scopus.com/inward/record.url?scp=70350442135&partnerID=8YFLogxK
M3 - Conference contribution
AN - SCOPUS:70350442135
SN - 9783832279431
T3 - Proceedings of 2009 2nd International Workshop on Nonlinear Dynamics and Synchronization, INDS 2009
SP - 203
EP - 208
BT - Proceedings of 2009 2nd International Workshop on Nonlinear Dynamics and Synchronization, INDS 2009
T2 - 2009 2nd International Workshop on Nonlinear Dynamics and Synchronization, INDS 2009
Y2 - 20 July 2009 through 21 July 2009
ER -