Building lightweight intrusion detection system using wrapper-based feature selection mechanisms
Autor: | Yang Li, Jun-Li Wang, Tian-Bo Lu, Zhihong Tian, Chen Young |
---|---|
Rok vydání: | 2009 |
Předmět: |
General Computer Science
Computer science Network security business.industry Anomaly-based intrusion detection system Feature selection Intrusion detection system computer.software_genre Machine learning Support vector machine Feature (computer vision) Pattern recognition (psychology) Data mining Artificial intelligence business Law computer Hill climbing |
Zdroj: | Computers & Security. 28:466-475 |
ISSN: | 0167-4048 |
DOI: | 10.1016/j.cose.2009.01.001 |
Popis: | Intrusion Detection System (IDS) is an important and necessary component in ensuring network security and protecting network resources and network infrastructures. How to build a lightweight IDS is a hot topic in network security. Moreover, feature selection is a classic research topic in data mining and it has attracted much interest from researchers in many fields such as network security, pattern recognition and data mining. In this paper, we effectively introduced feature selection methods to intrusion detection domain. We propose a wrapper-based feature selection algorithm aiming at building lightweight intrusion detection system by using modified random mutation hill climbing (RMHC) as search strategy to specify a candidate subset for evaluation, as well as using modified linear Support Vector Machines (SVMs) iterative procedure as wrapper approach to obtain the optimum feature subset. We verify the effectiveness and the feasibility of our feature selection algorithm by several experiments on KDD Cup 1999 intrusion detection dataset. The experimental results strongly show that our approach is not only able to speed up the process of selecting important features but also to yield high detection rates. Furthermore, our experimental results indicate that intrusion detection system with feature selection algorithm has better performance than that without feature selection algorithm both in detection performance and computational cost. |
Databáze: | OpenAIRE |
Externí odkaz: |