SVM for network anomaly detection using ACO feature subset

Over the past short time, network security facing a lot of challenges. Confidentiality, integrity, and availability are the major concerns of the data. To cope with this problem different systems have been developed and the systems are known as Intrusion detection systems. Intrusion detection system...

Full description

Saved in:
Bibliographic Details
Main Authors: Mehmood, T., Rais, H.B.M.
Format: Conference or Workshop Item
Published: Institute of Electrical and Electronics Engineers Inc. 2016
Online Access:https://www.scopus.com/inward/record.uri?eid=2-s2.0-84995603218&doi=10.1109%2fISMSC.2015.7594039&partnerID=40&md5=241b5ddc489a0a92397d9d3c2bee20f2
http://eprints.utp.edu.my/30918/
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utp.eprints.30918
record_format eprints
spelling my.utp.eprints.309182022-03-25T07:43:38Z SVM for network anomaly detection using ACO feature subset Mehmood, T. Rais, H.B.M. Over the past short time, network security facing a lot of challenges. Confidentiality, integrity, and availability are the major concerns of the data. To cope with this problem different systems have been developed and the systems are known as Intrusion detection systems. Intrusion detection system detects the violation of confidentiality, integrity, and availability of the data. Intrusion detection systems are developed on the bases of two different detection techniques, signature-based technique and anomaly-based technique. Classification approach has been widely adopted for the development of the anomaly detection model to classify the data into normal class and attack class. But irrelevant and redundant features are the obstacle for classification algorithm to build an efficient detection model. This paper proposes a detection model, ant system with support vector machine, which uses ant system, a variation of ant colony optimization, to filter out the redundant and irrelevant features for support vector machine classification algorithm. KDD99, which is a benchmark dataset used for anomaly detection, has been adopted here. Each instance in KDD99 has been represented by 41 features which also has some redundant or irrelevant features. Ant system has been used to remove those redundant and irrelevant features. The selected feature subset using ant system is then validated using support vector machine. The experimental results showed that the performance of the classification algorithm, when trained with the reduced feature set, has been improved. The performance measures used in this comparison are true positive rate, false positive rate, and precision. © 2015 IEEE. Institute of Electrical and Electronics Engineers Inc. 2016 Conference or Workshop Item NonPeerReviewed https://www.scopus.com/inward/record.uri?eid=2-s2.0-84995603218&doi=10.1109%2fISMSC.2015.7594039&partnerID=40&md5=241b5ddc489a0a92397d9d3c2bee20f2 Mehmood, T. and Rais, H.B.M. (2016) SVM for network anomaly detection using ACO feature subset. In: UNSPECIFIED. http://eprints.utp.edu.my/30918/
institution Universiti Teknologi Petronas
building UTP Resource Centre
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Petronas
content_source UTP Institutional Repository
url_provider http://eprints.utp.edu.my/
description Over the past short time, network security facing a lot of challenges. Confidentiality, integrity, and availability are the major concerns of the data. To cope with this problem different systems have been developed and the systems are known as Intrusion detection systems. Intrusion detection system detects the violation of confidentiality, integrity, and availability of the data. Intrusion detection systems are developed on the bases of two different detection techniques, signature-based technique and anomaly-based technique. Classification approach has been widely adopted for the development of the anomaly detection model to classify the data into normal class and attack class. But irrelevant and redundant features are the obstacle for classification algorithm to build an efficient detection model. This paper proposes a detection model, ant system with support vector machine, which uses ant system, a variation of ant colony optimization, to filter out the redundant and irrelevant features for support vector machine classification algorithm. KDD99, which is a benchmark dataset used for anomaly detection, has been adopted here. Each instance in KDD99 has been represented by 41 features which also has some redundant or irrelevant features. Ant system has been used to remove those redundant and irrelevant features. The selected feature subset using ant system is then validated using support vector machine. The experimental results showed that the performance of the classification algorithm, when trained with the reduced feature set, has been improved. The performance measures used in this comparison are true positive rate, false positive rate, and precision. © 2015 IEEE.
format Conference or Workshop Item
author Mehmood, T.
Rais, H.B.M.
spellingShingle Mehmood, T.
Rais, H.B.M.
SVM for network anomaly detection using ACO feature subset
author_facet Mehmood, T.
Rais, H.B.M.
author_sort Mehmood, T.
title SVM for network anomaly detection using ACO feature subset
title_short SVM for network anomaly detection using ACO feature subset
title_full SVM for network anomaly detection using ACO feature subset
title_fullStr SVM for network anomaly detection using ACO feature subset
title_full_unstemmed SVM for network anomaly detection using ACO feature subset
title_sort svm for network anomaly detection using aco feature subset
publisher Institute of Electrical and Electronics Engineers Inc.
publishDate 2016
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-84995603218&doi=10.1109%2fISMSC.2015.7594039&partnerID=40&md5=241b5ddc489a0a92397d9d3c2bee20f2
http://eprints.utp.edu.my/30918/
_version_ 1738657174969647104
score 13.214268