Research ArticleOpen AccessGoogle Scholar indexed
Tanimoto Based Similarity Measure for Intrusion Detection System
- 1
- 2
Journal of Information Security·Volume 02 (2011)·Pages 195–201·Published 24 October 2011·DOI10.4236/jis.2011.24019
Copy link · social · email
Abstract
In this paper we introduced Tanimoto based similarity measure for host-based intrusions using binary feature set for training and classification. The k-nearest neighbor (<i>k</i>NN) classifier has been utilized to classify a given process as either normal or attack. The experimentation is conducted on DARPA-1998 database for intrusion detection and compared with other existing techniques. The introduced similarity measure shows promising results by achieving less false positive rate at 100% detection rate.
KeywordsIntrusion Detection,<i>k</i>NN ClassifierSimilarity MeasureAnomaly DetectionTanimoto Similarity Measure
- T. Lane and C. E. Brodley, “Temporal Sequence Learning and Data Reduction for Anomaly Detection,” In Proceedings of 5th ACM Conference on Computer & Communication Security, San Francisco, November 3-5, 1998, pp. 150-158.
- Y. Yi, J. Wu and W. Xu, “Incremental SVM Based on Reserved Set for Network Intrusion Detection,” Expert Systems with Applications, Vol. 38, No. 6, 2011, pp. 7698- 7707. doi:10.1016/j.eswa.2010.12.141
- G. Wang, J. Hao, J. Ma and L. Huang, “A New Approach to Intrusion Detection Using Artificial Neural Networks and Fuzzy Clustering,” Expert Systems with Applications, Vol. 37, No. 9, 2010, pp. 6225-6232. doi:10.1016/j.eswa.2010.02.102
- C. F. Tsai, Y. F. Hsu, C. Y. Lin and W. Y. Lin, “Intrusion Detection by Machine Learning: A Review,” Expert Sys- tems with Applications, Vol. 36, No. 10, 2009, pp. 11994- 12000. doi:10.1016/j.eswa.2009.05.029
- Y. Liao and V. R. Vemuri, “Use of K-Nearest Neighbor Classifier for Intrusion Detection,” Computers & Security, Vol. 21, No. 5, 2002, pp. 439-448. doi:10.1016/S0167-4048(02)00514-X
- S. Rawat, V. P. Gulati, A. K. Pujari and V. R. Vemuri, “Intrusion Detection Using Text Processing Techniques with a Binary-Weighted Cosine Metric,” Journal of In- formation Assurance and Security, Vol. 1, 2006, pp. 43- 50.
- A. Sharma, A. K. Pujari and K. K. Paliwal, “Intrusion Detection Using Text Processing Techniques with a Kernel Based Similarity Measure,” Computers & Security, Vol. 26, No. 7-8, 2007, pp. 488-495. doi:10.1016/j.cose.2007.10.003
- D. E. Denning, “An Intrusion-Detection Model,” In Pro- ceedings of the 1986 IEEE Symposium on Security and Privacy (SSP ’86), IEEE Computer Society Pressm, 1990, pp. 118-133.
- T. Lane and C. E. Brodly. “An Application of Machine Learning to Anomaly Detection,” In Proceeding of the 20th National Information System Security Conference, Baltimore, MD, 1997, pp. 366-377.
- S. Forrest, S. A. Hofmeyr, A. Somayaji and T. A. Long- staff, “A Sense of Self for Unix Processes,” Proceedings of the 1996 IEEE Symposium on Research in Security and Privacy, Los Alamos, 1996, pp.120-128.
- S. Forrest, S. A. Hofmeyr and A. Somayaji, “Computer Immunology,” Communications of the ACM, Vol. 40, No. 10, 1997, pp. 88-96. doi:10.1145/262793.262811
- W. Lee, S. Stolfo and P. Chan. “Learning Patterns from Unix Process Execution Traces for Intrusion Detection,” In Proceedings of the AAAI97 Workshop on AI Methods in Fraud and Risk Management, AAAI Press, Menlo Park, 1997, pp. 50-56.