@brazovayeye

Applying Genetic Programming to Evolve Learned Rules for Network Anomaly Detection

, , , and . Advances in Natural Computation, First International Conference, ICNC 2005, Proceedings, Part III, volume 3612 of Lecture Notes in Computer Science, page 323--331. Changsha, China, Springer, (August 2005)
DOI: doi:10.1007/11539902_38

Abstract

The DARPA/MIT Lincoln Laboratory off-line intrusion detection evaluation data set is the most widely used public benchmark for testing intrusion detection systems. But the presence of simulation artifacts attributes would cause many attacks in this dataset to be easily detected. In order to eliminate their influence on intrusion detection, we simply omit these attributes in the processes of both training and testing. We also present a GP-based rule learning approach for detecting attacks on network. GP is used to evolve new rules from the initial learned rules through genetic operations. Our results show that GP-based rule learning approach outperforms the original rule learning algorithm, detecting 84 of 148 attacks at 100 false alarms despite the absence of several simulation artifacts attributes.

Links and resources

Tags

community

  • @brazovayeye
  • @dblp
@brazovayeye's tags highlighted