A three-level-module adaptive intrusion detection system

Lin Hui Zhao*, Yumin Wang, Jing Xiao, Ya Ping Dai, Fang Yan Dong, Hai Le Liu

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Citations (Scopus)

Abstract

Based on the Danger theory, the immune network theory and the decision templates fusion algorithm, a three-level-module adaptive intrusion detection system (TAIDS) is presented in this paper. To consider the effect of danger signals, the results of decision templates algorithm are redefined by adding a kind of suspicion signal. So, the detection templates should be modified online, and a template-adjustable adaptive decision fusion algorithm is proposed. There are two benefits in the TAIDS. First, when it is difficult to distinguish current behaviors depending on familiar features, The TAIDS will discriminate them by means of danger theory, making false alarms reduced and the ability of identifying novel attacks enhanced Second, the adaptive decision templates algorithm allows detection templates to modify dynamically without periodical updating. Experiments are carried out on KDD-CUP-99 database to verify the performance of this system. The false positive rate is 2.27%,and the accuracies on known attacks and on unknown attacks are respectively 97.67% and 98.75%.

Original languageEnglish
Title of host publication2007 IEEE International Conference on Networking, Sensing and Control, ICNSC'07
Pages840-845
Number of pages6
DOIs
Publication statusPublished - 2007
Event2007 IEEE International Conference on Networking, Sensing and Control, ICNSC'07 - London, United Kingdom
Duration: 15 Apr 200717 Apr 2007

Publication series

Name2007 IEEE International Conference on Networking, Sensing and Control, ICNSC'07

Conference

Conference2007 IEEE International Conference on Networking, Sensing and Control, ICNSC'07
Country/TerritoryUnited Kingdom
CityLondon
Period15/04/0717/04/07

Keywords

  • Danger theory
  • Data fusion algorithm
  • Intrusion detection

Fingerprint

Dive into the research topics of 'A three-level-module adaptive intrusion detection system'. Together they form a unique fingerprint.

Cite this