Cargando…
Intrusion Detection System Based on Pattern Recognition
Artificial intelligence has been developed to be able to solve difficult problems that involve huge amounts of data and that require rapid decision-making in most branches of science and business. Machine learning is one of the most prominent areas of artificial intelligence, which has been used hea...
Autor principal: | |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
Springer Berlin Heidelberg
2022
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9638289/ https://www.ncbi.nlm.nih.gov/pubmed/36373125 http://dx.doi.org/10.1007/s13369-022-07421-0 |
_version_ | 1784825373914038272 |
---|---|
author | Abdeldayem, Mohamed M. |
author_facet | Abdeldayem, Mohamed M. |
author_sort | Abdeldayem, Mohamed M. |
collection | PubMed |
description | Artificial intelligence has been developed to be able to solve difficult problems that involve huge amounts of data and that require rapid decision-making in most branches of science and business. Machine learning is one of the most prominent areas of artificial intelligence, which has been used heavily in the last two decades in the field of network security, especially in Intrusion Detection Systems (IDS). Pattern recognition is a machine learning method applied in medical applications, image processing, and video processing. In this article, two layers’ IDS is proposed. The first layer classifies the network connection according to the used service. Then, a minimum number of features that optimize the detection accuracy of malicious activities on that service are identified. Using those features, the second layer classifies each network connection as an attack or normal activity based on the pattern recognition method. In the training phase, two multivariate normal statistical models are created: the normal behavior model and the attack behavior model. In the testing and running phases, a maximum likelihood estimation function is used to classify a network connection into attack or normal activity using the two multivariate normal statistical models. The experimental results prove that the proposed IDS has superiority over related IDSs for network intrusion detection. Using only four features, it successfully achieves DR of 97.5%, 0.001 FAR, MCC 95.7%, and 99.8% overall accuracy. |
format | Online Article Text |
id | pubmed-9638289 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2022 |
publisher | Springer Berlin Heidelberg |
record_format | MEDLINE/PubMed |
spelling | pubmed-96382892022-11-07 Intrusion Detection System Based on Pattern Recognition Abdeldayem, Mohamed M. Arab J Sci Eng Research Article-Computer Engineering and Computer Science Artificial intelligence has been developed to be able to solve difficult problems that involve huge amounts of data and that require rapid decision-making in most branches of science and business. Machine learning is one of the most prominent areas of artificial intelligence, which has been used heavily in the last two decades in the field of network security, especially in Intrusion Detection Systems (IDS). Pattern recognition is a machine learning method applied in medical applications, image processing, and video processing. In this article, two layers’ IDS is proposed. The first layer classifies the network connection according to the used service. Then, a minimum number of features that optimize the detection accuracy of malicious activities on that service are identified. Using those features, the second layer classifies each network connection as an attack or normal activity based on the pattern recognition method. In the training phase, two multivariate normal statistical models are created: the normal behavior model and the attack behavior model. In the testing and running phases, a maximum likelihood estimation function is used to classify a network connection into attack or normal activity using the two multivariate normal statistical models. The experimental results prove that the proposed IDS has superiority over related IDSs for network intrusion detection. Using only four features, it successfully achieves DR of 97.5%, 0.001 FAR, MCC 95.7%, and 99.8% overall accuracy. Springer Berlin Heidelberg 2022-11-07 /pmc/articles/PMC9638289/ /pubmed/36373125 http://dx.doi.org/10.1007/s13369-022-07421-0 Text en © King Fahd University of Petroleum & Minerals 2022, Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law. This article is made available via the PMC Open Access Subset for unrestricted research re-use and secondary analysis in any form or by any means with acknowledgement of the original source. These permissions are granted for the duration of the World Health Organization (WHO) declaration of COVID-19 as a global pandemic. |
spellingShingle | Research Article-Computer Engineering and Computer Science Abdeldayem, Mohamed M. Intrusion Detection System Based on Pattern Recognition |
title | Intrusion Detection System Based on Pattern Recognition |
title_full | Intrusion Detection System Based on Pattern Recognition |
title_fullStr | Intrusion Detection System Based on Pattern Recognition |
title_full_unstemmed | Intrusion Detection System Based on Pattern Recognition |
title_short | Intrusion Detection System Based on Pattern Recognition |
title_sort | intrusion detection system based on pattern recognition |
topic | Research Article-Computer Engineering and Computer Science |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9638289/ https://www.ncbi.nlm.nih.gov/pubmed/36373125 http://dx.doi.org/10.1007/s13369-022-07421-0 |
work_keys_str_mv | AT abdeldayemmohamedm intrusiondetectionsystembasedonpatternrecognition |