Unknown Attack Detection: Combining Relabeling and Hybrid Intrusion Detection
- Authors
- Shin, Gun-Yoon; Kim, Dong-Wook; Kim, Sang-Soo; Han, Myung-Mook
- Issue Date
- May-2021
- Publisher
- TECH SCIENCE PRESS
- Keywords
- CART; Fuzzy c-means; Hybrid intrusion detection; IForest; Relabeling; Unknown attack
- Citation
- CMC-COMPUTERS MATERIALS & CONTINUA, v.68, no.3, pp.3289 - 3303
- Journal Title
- CMC-COMPUTERS MATERIALS & CONTINUA
- Volume
- 68
- Number
- 3
- Start Page
- 3289
- End Page
- 3303
- URI
- https://scholarworks.bwise.kr/gachon/handle/2020.sw.gachon/81196
- DOI
- 10.32604/cmc.2021.017502
- ISSN
- 1546-2218
- Abstract
- Detection of unknown attacks like a zero-day attack is a research field that has long been studied. Recently, advances in Machine Learning (ML) and Artificial Intelligence (AI) have led to the emergence of many kinds of attack-generation tools developed using these technologies to evade detection skillfully.Anomaly detection and misuse detection are themost commonly used techniques for detecting intrusion by unknown attacks. Although anomaly detection is adequate for detecting unknown attacks, its disadvantage is the possibility of high false alarms. Misuse detection has low false alarms; its limitation is that it can detect only known attacks. To overcome such limitations,many researchers have proposed a hybrid intrusion detection that integrates these two detection techniques. This method can overcome the limitations of conventional methods and works better in detecting unknown attacks. However, this method does not accurately classify attacks like similar to normal or known attacks. Therefore, we proposed a hybrid intrusion detection to detect unknown attacks similar to normal and known attacks. In anomaly detection, the model was designed to perform normal detection using Fuzzy c-means (FCM) and identify attacks hidden in normal predicted data using relabeling. In misuse detection, the model was designed to detect previously known attacks using Classification and Regression Trees (CART) and apply Isolation Forest (iForest) to classify unknown attacks hidden in known attacks.As an experiment result, the application of relabeling improved attack detection accuracy in anomaly detection by approximately 11% and enhanced the performance of unknown attack detection in misuse detection by approximately 10%. © 2021 Tech Science Press. All rights reserved.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - IT융합대학 > 소프트웨어학과 > 1. Journal Articles
![qrcode](https://api.qrserver.com/v1/create-qr-code/?size=55x55&data=https://scholarworks.bwise.kr/gachon/handle/2020.sw.gachon/81196)
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.