Use of decision trees and attributional rules in incremental learning of an intrusion detection model

In this paper, we propose a Learnable Model for Anomaly Detection (LMAD), as an ensemble real-time intrusion detection model using incremental supervised machine learning techniques. Such techniques are utilized to detect new attacks. The proposed model is based on making use of two different machine learning techniques, namely, decision trees and attributional rules classifiers. | International Journal of Computer Networks and Communications Security C VOL. 2, NO. 7, JULY 2014, 216–224 Available online at: ISSN 2308-9830 N C S Use of Decision Trees and Attributional Rules in Incremental Learning of an Intrusion Detection Model Abdurrahman A. Nasr1, Mohamed M. Ezz2, Mohamed Z. Abdulmageed3 1 Assistant lecturer, Al-Azhar University, Cairo, Egypt, Faculty of Engineering, Systems and Com. Dept. 2 Assistant professor, Al-Azhar University, Cairo, Egypt, Faculty of Engineering, Systems and Com. Dept. 3 Professor emeritus, Al-Azhar University, Cairo, Egypt, Faculty of Engineering, Systems and Com. Dept. E-mail: 1anasr@, , 3azhar@ ABSTRACT Current intrusion detection systems are mostly based on typical data mining techniques. The growing prevalence of new network attacks represents a well-known problem which can impact the availability, confidentiality, and integrity of critical information for both individuals and enterprises. In this paper, we propose a Learnable Model for Anomaly Detection (LMAD), as an ensemble real-time intrusion detection model using incremental supervised machine learning techniques. Such techniques are utilized to detect new attacks. The proposed model is based on making use of two different machine learning techniques, namely, decision trees and attributional rules classifiers. These classifiers comprise an ensemble that provides bagging for decision making. Our experimental results showed that, the model automatically learns new rules from continuous network stream, such that it can efficiently discriminate between anomaly and normal connections, offering the advantage of being deployed on any environment. The model is intensively tested online and its evaluation showed promising results. Keywords: Decision Trees, AQ, Incremental Classifier, Ensemble, Intrusion Detection. 1 INTRODUCTION Incremental learning addresses the ability of repeatedly .

Không thể tạo bản xem trước, hãy bấm tải xuống
TÀI LIỆU MỚI ĐĂNG
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.