Improving anomalous rare attack detection rate for intrusion detection system using support vector machine and genetic programming

Commonly addressed problem in intrusion detection system (IDS) research works that employed NSL-KDD dataset is to improve the rare attacks detection rate. However, some of the rare attacks are hard to be recognized by the IDS model due to their patterns are totally missing from the training set, hen...

Full description

Saved in:
Bibliographic Details
Main Authors: Mohd Pozi, Muhammad Syafiq, Sulaiman, Md. Nasir, Mustapha, Norwati, Perumal, Thinagaran
Format: Article
Language:English
Published: Springer Verlag 2016
Online Access:http://psasir.upm.edu.my/id/eprint/54525/1/Improving%20anomalous%20rare%20attack%20detection%20rate%20for%20intrusion%20detection%20system%20using%20support%20vector%20machine%20and%20genetic%20programming.pdf
http://psasir.upm.edu.my/id/eprint/54525/
https://link.springer.com/article/10.1007/s11063-015-9457-y
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Putra Malaysia
Language: English
Description
Summary:Commonly addressed problem in intrusion detection system (IDS) research works that employed NSL-KDD dataset is to improve the rare attacks detection rate. However, some of the rare attacks are hard to be recognized by the IDS model due to their patterns are totally missing from the training set, hence, reducing the rare attacks detection rate. This problem of missing rare attacks can be defined as anomalous rare attacks and hardly been solved in IDS literature. Hence, in this letter, we proposed a new classifier to improve the anomalous attacks detection rate based on support vector machine (SVM) and genetic programming (GP). Based on the experimental results, our classifier, GPSVM, managed to get higher detection rate on the anomalous rare attacks, without significant reduction on the overall accuracy. This is because, GPSVM optimization task is to ensure the accuracy is balanced between classes without reducing the generalization property of SVM.