Sciweavers

CISISSPAIN
2011

Testing Ensembles for Intrusion Detection: On the Identification of Mutated Network Scans

13 years 3 months ago
Testing Ensembles for Intrusion Detection: On the Identification of Mutated Network Scans
In last decades there have been many proposals from the machine learning community in the intrusion detection field. One of the main problems that Intrusion Detection Systems (IDSs) - mainly anomaly-based ones - have to face are those attacks not previously seen (zero-day attacks). This paper proposes a mutation technique to test and evaluate the performance of several classifier ensembles incorporated to network-based IDSs when tackling the task of recognizing such attacks. The technique applies mutant operators that randomly modifies the features of the captured packets to generate situations that otherwise could not be provided to learning IDSs. As an example application for the proposed testing model, it has been specially applied to the identification of network scans and related mutations.
Silvia González, Javier Sedano, Álva
Added 25 Aug 2011
Updated 25 Aug 2011
Type Journal
Year 2011
Where CISISSPAIN
Authors Silvia González, Javier Sedano, Álvaro Herrero, Bruno Baruque, Emilio Corchado
Comments (0)