Dimitrios Papamartzivanos, Félix Gómez Mármol, Georgios Kambourakis
Future Generation Computer Systems, vol. 79, no. 2, pp. 558-574
Publication year: 2018

Abstract

Intrusion detection systems (IDSs) are essential entities in a network topology aiming to safeguard the integrity and availability of sensitive assets in the protected systems. In misuse detection systems, which is the topic of the paper at hand, the detection process relies on specific attack signatures (rules) in an effort to distinguish between legitimate and malicious network traffic. Generally, three major challenges are associated with any IDS of this category: identifying patterns of new attacks with high accuracy, ameliorating the human-readability of the detection rules, and rightly designating the category these attacks belong to. To this end, we propose Dendron, a methodology for generating new detection rules which are able to classify both common and rare types of attacks. Our methodology takes advantage of both Decision Trees and Genetic Algorithms for the sake of evolving linguistically interpretable and accurate detection rules. It also integrates heuristic methods in the evolutionary process aiming to deal with the challenging nature of the network traffic, which generally biases machine learning techniques to neglect the minority classes of a dataset. The experimental results, using KDDCup’99, NSL-KDD and UNSW-NB15 datasets, reveal that Dendron is able to achieve superior results over other state-of-the-art and legacy techniques under several classification metrics, while at the same time is able to significantly detect rare intrusive incidents.

Related Publications


Improving attack detection in self-organizing networks: A trust-based approach toward alert satisfaction

Conference
Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez
4th International Conference on Advances in Computing, Communications and Informatics (ICACCI'15), pp. 1945-1951, ISBN: 978-1-4799-8790-0, Kerala, India
Publication year: 2015

RepCIDN: a reputation-based collaborative intrusion detection network to lessen the impact of malicious alarms

JournalQ4
Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez, Antonio F. Gómez Skarmeta
Journal of Network and Systems Management, vol. 21, no. 1, pp. 128-167
Publication year: 2013

Co-Authors

This work would not have been possible without the inestimable contribution of:

  • Dimitrios Papamartzivanos
  • Georgios Kambourakis

Dimitrios <br />Papamartzivanos

Dimitrios
Papamartzivanos

University of the Aegean
(Greece)

Web
Georgios <br />Kambourakis

Georgios
Kambourakis

University of the Aegean
(Greece)

Web

Citation

Dimitrios Papamartzivanos, Félix Gómez Mármol, Georgios Kambourakis, «Dendron: Genetic Trees driven Rule Induction for Network Intrusion Detection Systems«, Future Generation Computer Systems, vol. 79, no. 2, pp. 558-574, 2018

Journal Ranking & Impact Factor