Back to Search Start Over

An Approach for Anomaly Intrusion Detection Based on Causal Knowledge-Driven Diagnosis and Direction.

Authors :
Jazzar, Mahmoud
Jantan, Aman
Source :
Software Engineering, Artificial Intelligence, Networking & Parallel/distributed Computing; 2008, p39-48, 10p
Publication Year :
2008

Abstract

Conventional knowledge acquisition methods such as semantic knowledge, production rules and question answering systems have been addressed to a variety of typical knowledge based systems. However, very limited causal knowledge based methods have been addressed to the problem of intrusion detection. In this paper, we propose an approach based on causal knowledge reasoning for anomaly intrusion detection. Fuzzy cognitive maps (FCM) are ideal causal knowledge acquiring tool with fuzzy signed graphs which can be presented as an associative single layer neural network. Using FCM, our methodology attempt to diagnose and direct network traffic data based on its relevance to attack or normal connections. By quantifying the causal inference process we can determine the attack detection and the severity of odd packets. As such packets with low causal relations to attacks can be dropped or ignored and/or packets with high causal relations to attacks are to be highlighted. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISBNs :
9783540705598
Database :
Complementary Index
Journal :
Software Engineering, Artificial Intelligence, Networking & Parallel/distributed Computing
Publication Type :
Book
Accession number :
76876030
Full Text :
https://doi.org/10.1007/978-3-540-70560-4_4