Detailed Information

Cited 3 time in webofscience Cited 5 time in scopus
Metadata Downloads

Unknown Attack Detection: Combining Relabeling and Hybrid Intrusion Detection

Authors
Shin, Gun-YoonKim, Dong-WookKim, Sang-SooHan, Myung-Mook
Issue Date
May-2021
Publisher
TECH SCIENCE PRESS
Keywords
CART; Fuzzy c-means; Hybrid intrusion detection; IForest; Relabeling; Unknown attack
Citation
CMC-COMPUTERS MATERIALS & CONTINUA, v.68, no.3, pp.3289 - 3303
Journal Title
CMC-COMPUTERS MATERIALS & CONTINUA
Volume
68
Number
3
Start Page
3289
End Page
3303
URI
https://scholarworks.bwise.kr/gachon/handle/2020.sw.gachon/81196
DOI
10.32604/cmc.2021.017502
ISSN
1546-2218
Abstract
Detection of unknown attacks like a zero-day attack is a research field that has long been studied. Recently, advances in Machine Learning (ML) and Artificial Intelligence (AI) have led to the emergence of many kinds of attack-generation tools developed using these technologies to evade detection skillfully.Anomaly detection and misuse detection are themost commonly used techniques for detecting intrusion by unknown attacks. Although anomaly detection is adequate for detecting unknown attacks, its disadvantage is the possibility of high false alarms. Misuse detection has low false alarms; its limitation is that it can detect only known attacks. To overcome such limitations,many researchers have proposed a hybrid intrusion detection that integrates these two detection techniques. This method can overcome the limitations of conventional methods and works better in detecting unknown attacks. However, this method does not accurately classify attacks like similar to normal or known attacks. Therefore, we proposed a hybrid intrusion detection to detect unknown attacks similar to normal and known attacks. In anomaly detection, the model was designed to perform normal detection using Fuzzy c-means (FCM) and identify attacks hidden in normal predicted data using relabeling. In misuse detection, the model was designed to detect previously known attacks using Classification and Regression Trees (CART) and apply Isolation Forest (iForest) to classify unknown attacks hidden in known attacks.As an experiment result, the application of relabeling improved attack detection accuracy in anomaly detection by approximately 11% and enhanced the performance of unknown attack detection in misuse detection by approximately 10%. © 2021 Tech Science Press. All rights reserved.
Files in This Item
There are no files associated with this item.
Appears in
Collections
IT융합대학 > 소프트웨어학과 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Han, Myung Mook photo

Han, Myung Mook
IT (Department of Software)
Read more

Altmetrics

Total Views & Downloads

BROWSE