Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysi...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
Springer
2013-08-01
|
Series: | International Journal of Computational Intelligence Systems |
Subjects: | |
Online Access: | https://www.atlantis-press.com/article/25868410.pdf |
_version_ | 1811337781057683456 |
---|---|
author | Yuxin Meng Lam-For Kwok |
author_facet | Yuxin Meng Lam-For Kwok |
author_sort | Yuxin Meng |
collection | DOAJ |
description | Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level. |
first_indexed | 2024-04-13T18:00:47Z |
format | Article |
id | doaj.art-8acb21cad964490cafd7bf1aa8526d62 |
institution | Directory Open Access Journal |
issn | 1875-6883 |
language | English |
last_indexed | 2024-04-13T18:00:47Z |
publishDate | 2013-08-01 |
publisher | Springer |
record_format | Article |
series | International Journal of Computational Intelligence Systems |
spelling | doaj.art-8acb21cad964490cafd7bf1aa8526d622022-12-22T02:36:16ZengSpringerInternational Journal of Computational Intelligence Systems1875-68832013-08-016410.1080/18756891.2013.802114Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion DetectionYuxin MengLam-For KwokNetwork intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level.https://www.atlantis-press.com/article/25868410.pdfNetwork Intrusion DetectionIntelligent False Alarm ReductionEnsemble Selection |
spellingShingle | Yuxin Meng Lam-For Kwok Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection International Journal of Computational Intelligence Systems Network Intrusion Detection Intelligent False Alarm Reduction Ensemble Selection |
title | Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection |
title_full | Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection |
title_fullStr | Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection |
title_full_unstemmed | Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection |
title_short | Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection |
title_sort | enhancing false alarm reduction using voted ensemble selection in intrusion detection |
topic | Network Intrusion Detection Intelligent False Alarm Reduction Ensemble Selection |
url | https://www.atlantis-press.com/article/25868410.pdf |
work_keys_str_mv | AT yuxinmeng enhancingfalsealarmreductionusingvotedensembleselectioninintrusiondetection AT lamforkwok enhancingfalsealarmreductionusingvotedensembleselectioninintrusiondetection |