Mutating network scans for the assessment of supervised classifier ensembles
Loading...
Downloads
0
Date issued
Journal Title
Journal ISSN
Volume Title
Publisher
Oxford University Press
Location
Signature
Abstract
As it is well known, some Intrusion Detection Systems (IDSs) suffer from high rates of false positives and negatives. A mutation technique is proposed in this study to test and evaluate the performance of a full range of classifier ensembles for Network Intrusion Detection when trying to recognize new attacks. The novel technique applies mutant operators that randomly modify the features of the captured network packets to generate situations that could not otherwise be provided to IDSs while learning. A comprehensive comparison of supervised classifiers and their ensembles is performed to assess their generalization capability. It is based on the idea of confronting brand new network attacks obtained by means of the mutation technique. Finally, an example application of the proposed testing model is specially applied to the identification of network scans and related mutations.
Description
Subject(s)
network intrusion detection, IDS performance, classifier ensembles, machine learning, zero-day attacks, mutation
Citation
Logic Journal of the IGPL. 2013, vol. 21, issue 4, p. 630-647.
Item identifier
Collections
Publikační činnost VŠB-TUO ve Web of Science / Publications of VŠB-TUO in Web of Science
Publikační činnost IT4Innovations / Publications of IT4Innovations (9600)
Publikační činnost Katedry informatiky / Publications of Department of Computer Science (460)
Články z časopisů s impakt faktorem / Articles from Impact Factor Journals
Publikační činnost IT4Innovations / Publications of IT4Innovations (9600)
Publikační činnost Katedry informatiky / Publications of Department of Computer Science (460)
Články z časopisů s impakt faktorem / Articles from Impact Factor Journals