Back to Search
Start Over
Using Genetic Programming for Combining an Ensemble of Local and Global Outlier Algorithms to Detect New Attacks
- Source :
- Genetic and Evolutionary Computation Conference (GECCO-2019), Prague, Czech Republic, July 13th-17th 2019, info:cnr-pdr/source/autori:Gianluigi Folino, Francesco Sergio Pisani, Luigi Pontieri, Pietro Sabatino, Maryam Amir Haeri Amirkabir/congresso_nome:Genetic and Evolutionary Computation Conference (GECCO-2019)/congresso_luogo:Prague, Czech Republic/congresso_data:July 13th-17th 2019/anno:2019/pagina_da:/pagina_a:/intervallo_pagine, GECCO (Companion)
- Publication Year :
- 2019
-
Abstract
- Modern intrusion detection systems must be able to discover new types of attacks in real-time. To this aim, automatic or semi-automatic techniques can be used; outlier detection algorithms are particularly apt to this task, as they can work in an unsupervised way. However, due to the different nature and behavior of the attacks, the performance of different outlier detection algorithms varies largely. In this ongoing work, we describe an approach aimed at understanding whether an ensemble of outlier algorithms can be used to detect effectively new types of attacks in intrusion detection systems. In particular, Genetic Programming (GP) is adopted to build the combining function of an ensemble of local and global outlier detection algorithms, which are used to detect different types of attack. Preliminary experiments, conducted on the well-known NSL-KDD dataset, are encouraging and confirm that, depending on the type of attacks, it would be better to use only local or only global detection algorithms and that the GP-based ensemble improves the performance in comparison with commonly used combining functions.
- Subjects :
- Cybersecurity
Computer science
media_common.quotation_subject
Genetic programming
0102 computer and information sciences
02 engineering and technology
Intrusion detection system
01 natural sciences
Task (computing)
010201 computation theory & mathematics
Classifier ensembles
Outlier
0202 electrical engineering, electronic engineering, information engineering
020201 artificial intelligence & image processing
Anomaly detection
Intrusion detection
Function (engineering)
Algorithm
media_common
Subjects
Details
- Language :
- English
- Database :
- OpenAIRE
- Journal :
- Genetic and Evolutionary Computation Conference (GECCO-2019), Prague, Czech Republic, July 13th-17th 2019, info:cnr-pdr/source/autori:Gianluigi Folino, Francesco Sergio Pisani, Luigi Pontieri, Pietro Sabatino, Maryam Amir Haeri Amirkabir/congresso_nome:Genetic and Evolutionary Computation Conference (GECCO-2019)/congresso_luogo:Prague, Czech Republic/congresso_data:July 13th-17th 2019/anno:2019/pagina_da:/pagina_a:/intervallo_pagine, GECCO (Companion)
- Accession number :
- edsair.doi.dedup.....827b1ecb3fb9213bfa08b93c94cf7b89