Cargando…

Intrusion Detection System Based on Pattern Recognition

Artificial intelligence has been developed to be able to solve difficult problems that involve huge amounts of data and that require rapid decision-making in most branches of science and business. Machine learning is one of the most prominent areas of artificial intelligence, which has been used hea...

Descripción completa

Detalles Bibliográficos
Autor principal: Abdeldayem, Mohamed M.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Springer Berlin Heidelberg 2022
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9638289/
https://www.ncbi.nlm.nih.gov/pubmed/36373125
http://dx.doi.org/10.1007/s13369-022-07421-0
_version_ 1784825373914038272
author Abdeldayem, Mohamed M.
author_facet Abdeldayem, Mohamed M.
author_sort Abdeldayem, Mohamed M.
collection PubMed
description Artificial intelligence has been developed to be able to solve difficult problems that involve huge amounts of data and that require rapid decision-making in most branches of science and business. Machine learning is one of the most prominent areas of artificial intelligence, which has been used heavily in the last two decades in the field of network security, especially in Intrusion Detection Systems (IDS). Pattern recognition is a machine learning method applied in medical applications, image processing, and video processing. In this article, two layers’ IDS is proposed. The first layer classifies the network connection according to the used service. Then, a minimum number of features that optimize the detection accuracy of malicious activities on that service are identified. Using those features, the second layer classifies each network connection as an attack or normal activity based on the pattern recognition method. In the training phase, two multivariate normal statistical models are created: the normal behavior model and the attack behavior model. In the testing and running phases, a maximum likelihood estimation function is used to classify a network connection into attack or normal activity using the two multivariate normal statistical models. The experimental results prove that the proposed IDS has superiority over related IDSs for network intrusion detection. Using only four features, it successfully achieves DR of 97.5%, 0.001 FAR, MCC 95.7%, and 99.8% overall accuracy.
format Online
Article
Text
id pubmed-9638289
institution National Center for Biotechnology Information
language English
publishDate 2022
publisher Springer Berlin Heidelberg
record_format MEDLINE/PubMed
spelling pubmed-96382892022-11-07 Intrusion Detection System Based on Pattern Recognition Abdeldayem, Mohamed M. Arab J Sci Eng Research Article-Computer Engineering and Computer Science Artificial intelligence has been developed to be able to solve difficult problems that involve huge amounts of data and that require rapid decision-making in most branches of science and business. Machine learning is one of the most prominent areas of artificial intelligence, which has been used heavily in the last two decades in the field of network security, especially in Intrusion Detection Systems (IDS). Pattern recognition is a machine learning method applied in medical applications, image processing, and video processing. In this article, two layers’ IDS is proposed. The first layer classifies the network connection according to the used service. Then, a minimum number of features that optimize the detection accuracy of malicious activities on that service are identified. Using those features, the second layer classifies each network connection as an attack or normal activity based on the pattern recognition method. In the training phase, two multivariate normal statistical models are created: the normal behavior model and the attack behavior model. In the testing and running phases, a maximum likelihood estimation function is used to classify a network connection into attack or normal activity using the two multivariate normal statistical models. The experimental results prove that the proposed IDS has superiority over related IDSs for network intrusion detection. Using only four features, it successfully achieves DR of 97.5%, 0.001 FAR, MCC 95.7%, and 99.8% overall accuracy. Springer Berlin Heidelberg 2022-11-07 /pmc/articles/PMC9638289/ /pubmed/36373125 http://dx.doi.org/10.1007/s13369-022-07421-0 Text en © King Fahd University of Petroleum & Minerals 2022, Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law. This article is made available via the PMC Open Access Subset for unrestricted research re-use and secondary analysis in any form or by any means with acknowledgement of the original source. These permissions are granted for the duration of the World Health Organization (WHO) declaration of COVID-19 as a global pandemic.
spellingShingle Research Article-Computer Engineering and Computer Science
Abdeldayem, Mohamed M.
Intrusion Detection System Based on Pattern Recognition
title Intrusion Detection System Based on Pattern Recognition
title_full Intrusion Detection System Based on Pattern Recognition
title_fullStr Intrusion Detection System Based on Pattern Recognition
title_full_unstemmed Intrusion Detection System Based on Pattern Recognition
title_short Intrusion Detection System Based on Pattern Recognition
title_sort intrusion detection system based on pattern recognition
topic Research Article-Computer Engineering and Computer Science
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9638289/
https://www.ncbi.nlm.nih.gov/pubmed/36373125
http://dx.doi.org/10.1007/s13369-022-07421-0
work_keys_str_mv AT abdeldayemmohamedm intrusiondetectionsystembasedonpatternrecognition