Efficient feature selection and classification through ensemble method for network intrusion detection on cloud computing

Efficient feature selection and classification through ensemble method for network intrusion detection on cloud computing
复制标题

DOI:
10.1007/s10586-020-03222-y
复制
发表时间:
2021-01-02
影响因子:
4.4
通讯作者:
Prabakaran, S.
Prabakaran, S.
中科院分区:
计算机科学4区
文献类型:
--
作者:
Krishnaveni, S.;Sivamohan, S.;Prabakaran, S.

文献摘要

被引文献

相似文献

云计算是全球组织的首选,它作为一种灵活的服务提供可扩展的和基于互联网的计算资源。由于其分布式特性,安全性是任何云解决方案的一个关键关注因素。安全性和隐私是其按需服务成功面临的巨大障碍,因为它很容易受到任何形式的攻击。网络流量的激增为更为复杂和广泛的安全漏洞铺平了道路。传统入侵检测系统(IDS)环境对此类攻击的处理效率低下。在本研究中,我们利用集成特征选择和分类技术开发了一种高效的云环境入侵检测系统(IDS)。该方法基于单变量集成特征选择技术,用于从给定的入侵数据集中选择有价值的约简特征集。而集成分类器则可以使用投票技术有效地融合单个分类器以产生鲁棒分类器。提出了一种基于集成的网络流量行为分类方法。通过在各种分类器上应用各种性能评估指标和ROC-AUC(“接收者工作特征曲线下的面积”)来衡量所提出方法的实施情况。与其他现有方法相比,所提出方法的结果取得了相当大的性能增强。此外,我们进行了两两t检验,证明所提出的方法的性能与其他现有方法有统计学显著差异。最后,以最佳的准确率和最低的虚警率(FAR)获得了本调查的结果。
Cloud computing is a preferred option for organizations around the globe, it offers scalable and internet-based computing resources as a flexible service. Security is a key concern factor in any cloud solution due to its distributed nature. Security and privacy are huge obstacles faced in its success of the on-demand service as it is easily vulnerable to intruders for any kind of attack. A huge upsurge in network traffic has paved the way to security breaches which are more complicated and widespread. Tackling these attacks has become an inefficient application of traditional intrusion detection systems (IDS) environment. In this research, we developed an efficient Intrusion Detection System (IDS) for the cloud environment using ensemble feature selection and classification techniques. This proposed method was relying on the univariate ensemble feature selection technique, which is used for the selection of valuable reduced feature sets from the given intrusion datasets. While the ensemble classifiers that can competently fuse the single classifiers to produce a robust classifier using the voting technique. An ensemble based proposed method effectively classifies whether the network traffic behavior is normal or attack. The implementation of the proposed method was measured by applying various performance evaluation metrics and ROC-AUC ("area under the receiver operating characteristic curves") across various classifiers. The results of the proposed methodology achieved a strong considerable amount of performance enhancement compared with other existing methods. Moreover, we performed a pairwise t test and proved that the performance of the proposed method was statistically significantly different from other existing approaches. Finally, the outcome of this investigation was obtained with the best accuracy and lowest false alarm rate (FAR).