Back to Search
Start Over
An Approach for Anomaly Intrusion Detection Based on Causal Knowledge-Driven Diagnosis and Direction.
- Source :
- Software Engineering, Artificial Intelligence, Networking & Parallel/distributed Computing; 2008, p39-48, 10p
- Publication Year :
- 2008
-
Abstract
- Conventional knowledge acquisition methods such as semantic knowledge, production rules and question answering systems have been addressed to a variety of typical knowledge based systems. However, very limited causal knowledge based methods have been addressed to the problem of intrusion detection. In this paper, we propose an approach based on causal knowledge reasoning for anomaly intrusion detection. Fuzzy cognitive maps (FCM) are ideal causal knowledge acquiring tool with fuzzy signed graphs which can be presented as an associative single layer neural network. Using FCM, our methodology attempt to diagnose and direct network traffic data based on its relevance to attack or normal connections. By quantifying the causal inference process we can determine the attack detection and the severity of odd packets. As such packets with low causal relations to attacks can be dropped or ignored and/or packets with high causal relations to attacks are to be highlighted. [ABSTRACT FROM AUTHOR]
Details
- Language :
- English
- ISBNs :
- 9783540705598
- Database :
- Complementary Index
- Journal :
- Software Engineering, Artificial Intelligence, Networking & Parallel/distributed Computing
- Publication Type :
- Book
- Accession number :
- 76876030
- Full Text :
- https://doi.org/10.1007/978-3-540-70560-4_4