Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM

Anomaly Intrusion Detection Systems (ADSs) identify patterns of network data behaviour to determine whether they are normal or represent an attack using the learning detection model. Much research has been conducted on enhancing ADSs particularly in the area of data mining that focuses on intrusive...

Full description

Saved in:
Bibliographic Details
Main Authors: Mohamed Yassin, Warusia, Abdollah, Mohd Faizal, Mas'ud, Mohd Zaki, Yusof, Robiah, Abdullah, Raihana Syahirah, Muda, Zaiton
Format: Article
Language:English
Published: Little Lion Scientific 2018
Online Access:http://psasir.upm.edu.my/id/eprint/72575/1/Enhanced%20intrusion%20detection%20capabilities%20.pdf
http://psasir.upm.edu.my/id/eprint/72575/
http://www.jatit.org/volumes/ninetysix18.php
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.upm.eprints.72575
record_format eprints
spelling my.upm.eprints.725752020-11-03T04:19:02Z http://psasir.upm.edu.my/id/eprint/72575/ Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM Mohamed Yassin, Warusia Abdollah, Mohd Faizal Mas'ud, Mohd Zaki Yusof, Robiah Abdullah, Raihana Syahirah Muda, Zaiton Anomaly Intrusion Detection Systems (ADSs) identify patterns of network data behaviour to determine whether they are normal or represent an attack using the learning detection model. Much research has been conducted on enhancing ADSs particularly in the area of data mining that focuses on intrusive behaviour detection. Unfortunately, the current detection models such as the support vector machine (SVM) is affected by high dimensional data which limits its ability to accurately classify data. Moreover, the data points which appear similar between intrusive and regular behaviours could be problematic as some innovated attack behaviours may not be detected. To overcome this SVM drawback, we propose a combination of weighted chi-square (WCS) as a feature selection (FS) and a Discretization process (D). The WCS method is used firstly to reduce the dimensionality of data following which the assembled records are transformed into interval values via the D process before the SVM is used to identify groups of samples that behave similarly and dissimilarly such as malicious and non-malicious activities. Experiments were performed with well-known NSL-KDD data sets and the results show that the proposed method namely WCS-D-SVM (weighted chi-square, discretization and support vector machine) significantly improved and enhanced accuracy and detection rates while decreasing the false positives which the single SVM classifier produces. Little Lion Scientific 2018-09 Article PeerReviewed text en http://psasir.upm.edu.my/id/eprint/72575/1/Enhanced%20intrusion%20detection%20capabilities%20.pdf Mohamed Yassin, Warusia and Abdollah, Mohd Faizal and Mas'ud, Mohd Zaki and Yusof, Robiah and Abdullah, Raihana Syahirah and Muda, Zaiton (2018) Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM. Journal of Theoretical and Applied Information Technology, 96 (18). 6006 - 6017. ISSN 1992-8645; ESSN: 1817-3195 http://www.jatit.org/volumes/ninetysix18.php
institution Universiti Putra Malaysia
building UPM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Putra Malaysia
content_source UPM Institutional Repository
url_provider http://psasir.upm.edu.my/
language English
description Anomaly Intrusion Detection Systems (ADSs) identify patterns of network data behaviour to determine whether they are normal or represent an attack using the learning detection model. Much research has been conducted on enhancing ADSs particularly in the area of data mining that focuses on intrusive behaviour detection. Unfortunately, the current detection models such as the support vector machine (SVM) is affected by high dimensional data which limits its ability to accurately classify data. Moreover, the data points which appear similar between intrusive and regular behaviours could be problematic as some innovated attack behaviours may not be detected. To overcome this SVM drawback, we propose a combination of weighted chi-square (WCS) as a feature selection (FS) and a Discretization process (D). The WCS method is used firstly to reduce the dimensionality of data following which the assembled records are transformed into interval values via the D process before the SVM is used to identify groups of samples that behave similarly and dissimilarly such as malicious and non-malicious activities. Experiments were performed with well-known NSL-KDD data sets and the results show that the proposed method namely WCS-D-SVM (weighted chi-square, discretization and support vector machine) significantly improved and enhanced accuracy and detection rates while decreasing the false positives which the single SVM classifier produces.
format Article
author Mohamed Yassin, Warusia
Abdollah, Mohd Faizal
Mas'ud, Mohd Zaki
Yusof, Robiah
Abdullah, Raihana Syahirah
Muda, Zaiton
spellingShingle Mohamed Yassin, Warusia
Abdollah, Mohd Faizal
Mas'ud, Mohd Zaki
Yusof, Robiah
Abdullah, Raihana Syahirah
Muda, Zaiton
Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM
author_facet Mohamed Yassin, Warusia
Abdollah, Mohd Faizal
Mas'ud, Mohd Zaki
Yusof, Robiah
Abdullah, Raihana Syahirah
Muda, Zaiton
author_sort Mohamed Yassin, Warusia
title Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM
title_short Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM
title_full Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM
title_fullStr Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM
title_full_unstemmed Enhanced intrusion detection capabilities via weighted chi-square, discretization and SVM
title_sort enhanced intrusion detection capabilities via weighted chi-square, discretization and svm
publisher Little Lion Scientific
publishDate 2018
url http://psasir.upm.edu.my/id/eprint/72575/1/Enhanced%20intrusion%20detection%20capabilities%20.pdf
http://psasir.upm.edu.my/id/eprint/72575/
http://www.jatit.org/volumes/ninetysix18.php
_version_ 1683232214704193536
score 13.211869