Back to Search Start Over

Using Genetic Programming for Combining an Ensemble of Local and Global Outlier Algorithms to Detect New Attacks

Authors :
Maryam Amir Haeri
Francesco Sergio Pisani
Gianluigi Folino
Pietro Sabatino
Luigi Pontieri
Source :
Genetic and Evolutionary Computation Conference (GECCO-2019), Prague, Czech Republic, July 13th-17th 2019, info:cnr-pdr/source/autori:Gianluigi Folino, Francesco Sergio Pisani, Luigi Pontieri, Pietro Sabatino, Maryam Amir Haeri Amirkabir/congresso_nome:Genetic and Evolutionary Computation Conference (GECCO-2019)/congresso_luogo:Prague, Czech Republic/congresso_data:July 13th-17th 2019/anno:2019/pagina_da:/pagina_a:/intervallo_pagine, GECCO (Companion)
Publication Year :
2019

Abstract

Modern intrusion detection systems must be able to discover new types of attacks in real-time. To this aim, automatic or semi-automatic techniques can be used; outlier detection algorithms are particularly apt to this task, as they can work in an unsupervised way. However, due to the different nature and behavior of the attacks, the performance of different outlier detection algorithms varies largely. In this ongoing work, we describe an approach aimed at understanding whether an ensemble of outlier algorithms can be used to detect effectively new types of attacks in intrusion detection systems. In particular, Genetic Programming (GP) is adopted to build the combining function of an ensemble of local and global outlier detection algorithms, which are used to detect different types of attack. Preliminary experiments, conducted on the well-known NSL-KDD dataset, are encouraging and confirm that, depending on the type of attacks, it would be better to use only local or only global detection algorithms and that the GP-based ensemble improves the performance in comparison with commonly used combining functions.

Details

Language :
English
Database :
OpenAIRE
Journal :
Genetic and Evolutionary Computation Conference (GECCO-2019), Prague, Czech Republic, July 13th-17th 2019, info:cnr-pdr/source/autori:Gianluigi Folino, Francesco Sergio Pisani, Luigi Pontieri, Pietro Sabatino, Maryam Amir Haeri Amirkabir/congresso_nome:Genetic and Evolutionary Computation Conference (GECCO-2019)/congresso_luogo:Prague, Czech Republic/congresso_data:July 13th-17th 2019/anno:2019/pagina_da:/pagina_a:/intervallo_pagine, GECCO (Companion)
Accession number :
edsair.doi.dedup.....827b1ecb3fb9213bfa08b93c94cf7b89