Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm

Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm
复制标题

基于过滤器特征选择算法的入侵检测系统

DOI:
10.1109/tc.2016.2519914
复制
发表时间:
2016-10-01
影响因子:
3.7
通讯作者:
Tan, Zhiyuan
Tan, Zhiyuan
中科院分区:
计算机科学2区
文献类型:
--
作者:
Ambusaidi, Mohammed A.;He, Xiangjian;Tan, Zhiyuan

文献摘要

被引文献

相似文献

数据中冗余和不相关的特征一直是网络流量分类的一大难题。这些特征不仅减慢了分类过程,也阻碍了分类器做出准确的决策,尤其是在处理大数据时。在本文中,我们提出了一种基于互信息的算法,可以解析地选择最优特征进行分类。这种基于互信息的特征选择算法可以处理线性和非线性相关的数据特征。以网络入侵检测为例,对其有效性进行了评价。基于最小二乘支持向量机的入侵检测系统(LSSVM-IDS)是利用我们提出的特征选择算法所选择的特征构建的。利用KDD Cup 99、NSL-KDD和Kyoto 2006+三个入侵检测评估数据集对LSSVM-IDS的性能进行了评估。评估结果表明,与现有方法相比,我们的特征选择算法为LSSVM-IDS贡献了更多的关键特征,达到了更高的准确率和更低的计算成本。
Redundant and irrelevant features in data have caused a long-term problem in network traffic classification. These features not only slow down the process of classification but also prevent a classifier from making accurate decisions, especially when coping with big data. In this paper, we propose a mutual information based algorithm that analytically selects the optimal feature for classification. This mutual information based feature selection algorithm can handle linearly and nonlinearly dependent data features. Its effectiveness is evaluated in the cases of network intrusion detection. An Intrusion Detection System (IDS), named Least Square Support Vector Machine based IDS (LSSVM-IDS), is built using the features selected by our proposed feature selection algorithm. The performance of LSSVM-IDS is evaluated using three intrusion detection evaluation datasets, namely KDD Cup 99, NSL-KDD and Kyoto 2006+ dataset. The evaluation results show that our feature selection algorithm contributes more critical features for LSSVM-IDS to achieve better accuracy and lower computational cost compared with the state-of-the-art methods.