Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection

Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysi...

Full description

Bibliographic Details
Main Authors: Yuxin Meng, Lam-For Kwok
Format: Article
Language:English
Published: Springer 2013-08-01
Series:International Journal of Computational Intelligence Systems
Subjects:
Online Access:https://www.atlantis-press.com/article/25868410.pdf
_version_ 1811337781057683456
author Yuxin Meng
Lam-For Kwok
author_facet Yuxin Meng
Lam-For Kwok
author_sort Yuxin Meng
collection DOAJ
description Network intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level.
first_indexed 2024-04-13T18:00:47Z
format Article
id doaj.art-8acb21cad964490cafd7bf1aa8526d62
institution Directory Open Access Journal
issn 1875-6883
language English
last_indexed 2024-04-13T18:00:47Z
publishDate 2013-08-01
publisher Springer
record_format Article
series International Journal of Computational Intelligence Systems
spelling doaj.art-8acb21cad964490cafd7bf1aa8526d622022-12-22T02:36:16ZengSpringerInternational Journal of Computational Intelligence Systems1875-68832013-08-016410.1080/18756891.2013.802114Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion DetectionYuxin MengLam-For KwokNetwork intrusion detection systems (NIDSs) have become an indispensable component for the current network security infrastructure. However, a large number of alarms especially false alarms are a big problem for these systems which greatly lowers the effectiveness of NIDSs and causes heavier analysis workload. To address this problem, a lot of intelligent methods (e.g., machine learning algorithms) have been proposed to reduce the number of false alarms, but it is hard to determine which one is the best. We argue that the performance of different machine learning algorithms is very fluctuant with regard to distinct contexts (e.g., training data). In this paper, we propose an architecture of intelligent false alarm filter by employing a method of voted ensemble selection aiming to maintain the accuracy of false alarm reduction. In particular, there are four components in the architecture: data standardization, data storage, voted ensemble selection and alarm filtration. In the experiment, we conduct a study involved three machine learning algorithms such as support vector machine, decision tree and k-nearest neighbor, and use Snort, which is an open source signature-based NIDS, to explore the effectiveness of our proposed architecture. The experimental results show that our intelligent false alarm filter is effective and encouraging to maintain the performance of reducing false alarms at a high and stable level.https://www.atlantis-press.com/article/25868410.pdfNetwork Intrusion DetectionIntelligent False Alarm ReductionEnsemble Selection
spellingShingle Yuxin Meng
Lam-For Kwok
Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
International Journal of Computational Intelligence Systems
Network Intrusion Detection
Intelligent False Alarm Reduction
Ensemble Selection
title Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
title_full Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
title_fullStr Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
title_full_unstemmed Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
title_short Enhancing False Alarm Reduction Using Voted Ensemble Selection in Intrusion Detection
title_sort enhancing false alarm reduction using voted ensemble selection in intrusion detection
topic Network Intrusion Detection
Intelligent False Alarm Reduction
Ensemble Selection
url https://www.atlantis-press.com/article/25868410.pdf
work_keys_str_mv AT yuxinmeng enhancingfalsealarmreductionusingvotedensembleselectioninintrusiondetection
AT lamforkwok enhancingfalsealarmreductionusingvotedensembleselectioninintrusiondetection