SVM for network anomaly detection using ACO feature subset
Over the past short time, network security facing a lot of challenges. Confidentiality, integrity, and availability are the major concerns of the data. To cope with this problem different systems have been developed and the systems are known as Intrusion detection systems. Intrusion detection system...
Saved in:
Main Authors: | , |
---|---|
Format: | Conference or Workshop Item |
Published: |
Institute of Electrical and Electronics Engineers Inc.
2016
|
Online Access: | https://www.scopus.com/inward/record.uri?eid=2-s2.0-84995603218&doi=10.1109%2fISMSC.2015.7594039&partnerID=40&md5=241b5ddc489a0a92397d9d3c2bee20f2 http://eprints.utp.edu.my/30918/ |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
id |
my.utp.eprints.30918 |
---|---|
record_format |
eprints |
spelling |
my.utp.eprints.309182022-03-25T07:43:38Z SVM for network anomaly detection using ACO feature subset Mehmood, T. Rais, H.B.M. Over the past short time, network security facing a lot of challenges. Confidentiality, integrity, and availability are the major concerns of the data. To cope with this problem different systems have been developed and the systems are known as Intrusion detection systems. Intrusion detection system detects the violation of confidentiality, integrity, and availability of the data. Intrusion detection systems are developed on the bases of two different detection techniques, signature-based technique and anomaly-based technique. Classification approach has been widely adopted for the development of the anomaly detection model to classify the data into normal class and attack class. But irrelevant and redundant features are the obstacle for classification algorithm to build an efficient detection model. This paper proposes a detection model, ant system with support vector machine, which uses ant system, a variation of ant colony optimization, to filter out the redundant and irrelevant features for support vector machine classification algorithm. KDD99, which is a benchmark dataset used for anomaly detection, has been adopted here. Each instance in KDD99 has been represented by 41 features which also has some redundant or irrelevant features. Ant system has been used to remove those redundant and irrelevant features. The selected feature subset using ant system is then validated using support vector machine. The experimental results showed that the performance of the classification algorithm, when trained with the reduced feature set, has been improved. The performance measures used in this comparison are true positive rate, false positive rate, and precision. © 2015 IEEE. Institute of Electrical and Electronics Engineers Inc. 2016 Conference or Workshop Item NonPeerReviewed https://www.scopus.com/inward/record.uri?eid=2-s2.0-84995603218&doi=10.1109%2fISMSC.2015.7594039&partnerID=40&md5=241b5ddc489a0a92397d9d3c2bee20f2 Mehmood, T. and Rais, H.B.M. (2016) SVM for network anomaly detection using ACO feature subset. In: UNSPECIFIED. http://eprints.utp.edu.my/30918/ |
institution |
Universiti Teknologi Petronas |
building |
UTP Resource Centre |
collection |
Institutional Repository |
continent |
Asia |
country |
Malaysia |
content_provider |
Universiti Teknologi Petronas |
content_source |
UTP Institutional Repository |
url_provider |
http://eprints.utp.edu.my/ |
description |
Over the past short time, network security facing a lot of challenges. Confidentiality, integrity, and availability are the major concerns of the data. To cope with this problem different systems have been developed and the systems are known as Intrusion detection systems. Intrusion detection system detects the violation of confidentiality, integrity, and availability of the data. Intrusion detection systems are developed on the bases of two different detection techniques, signature-based technique and anomaly-based technique. Classification approach has been widely adopted for the development of the anomaly detection model to classify the data into normal class and attack class. But irrelevant and redundant features are the obstacle for classification algorithm to build an efficient detection model. This paper proposes a detection model, ant system with support vector machine, which uses ant system, a variation of ant colony optimization, to filter out the redundant and irrelevant features for support vector machine classification algorithm. KDD99, which is a benchmark dataset used for anomaly detection, has been adopted here. Each instance in KDD99 has been represented by 41 features which also has some redundant or irrelevant features. Ant system has been used to remove those redundant and irrelevant features. The selected feature subset using ant system is then validated using support vector machine. The experimental results showed that the performance of the classification algorithm, when trained with the reduced feature set, has been improved. The performance measures used in this comparison are true positive rate, false positive rate, and precision. © 2015 IEEE. |
format |
Conference or Workshop Item |
author |
Mehmood, T. Rais, H.B.M. |
spellingShingle |
Mehmood, T. Rais, H.B.M. SVM for network anomaly detection using ACO feature subset |
author_facet |
Mehmood, T. Rais, H.B.M. |
author_sort |
Mehmood, T. |
title |
SVM for network anomaly detection using ACO feature subset |
title_short |
SVM for network anomaly detection using ACO feature subset |
title_full |
SVM for network anomaly detection using ACO feature subset |
title_fullStr |
SVM for network anomaly detection using ACO feature subset |
title_full_unstemmed |
SVM for network anomaly detection using ACO feature subset |
title_sort |
svm for network anomaly detection using aco feature subset |
publisher |
Institute of Electrical and Electronics Engineers Inc. |
publishDate |
2016 |
url |
https://www.scopus.com/inward/record.uri?eid=2-s2.0-84995603218&doi=10.1109%2fISMSC.2015.7594039&partnerID=40&md5=241b5ddc489a0a92397d9d3c2bee20f2 http://eprints.utp.edu.my/30918/ |
_version_ |
1738657174969647104 |
score |
13.214268 |