Electronic Resource
Boston, USA and Oxford, UK
:
Blackwell Publishing, Inc.
Computational intelligence
20 (2004), S. 0
ISSN:
1467-8640
Source:
Blackwell Publishing Journal Backfiles 1879-2005
Topics:
Computer Science
Notes:
How to find and detect novel or unknown network attacks is one of the most important objectives in current intrusion detection systems. In this paper, a rule evolution approach based on Genetic Programming (GP) for detecting novel attacks on networks is presented and four genetic operators, namely reproduction, mutation, crossover, and dropping condition operators, are used to evolve new rules. New rules are used to detect novel or known network attacks. A training and testing dataset proposed by DARPA is used to evolve and evaluate these new rules. The proof of concept implementation shows that a rule generated by GP has a low false positive rate (FPR), a low false negative rate and a high rate of detecting unknown attacks. Moreover, the rule base composed of new rules has high detection rate with low FPR. An alternative to the DARPA evaluation approach is also investigated.
Type of Medium:
Electronic Resource
URL:
http://dx.doi.org/10.1111/j.0824-7935.2004.00247.x
Permalink
|
Location |
Call Number |
Expected |
Availability |