A Novel Approach to Optimize the Performance of Network Based IDS Using Enhanced EBPA and Ant Colony Optimization

Abstract

Due to the recent developments and revolutions in the field of Technology and newlineInternet at a rapid pace, the domain of Computer and Network Security has been of keen newlineinterest to the Researchers, Developers and Hackers. Due to these developments in the newlinedomain of Internet, Hackers and Attackers got an opportunity to access the Resources, newlineServices and Data over Internet through unfair means using the bottlenecks of these newlinedevelopments, as nothing is 100 % perfect in this world; each and every entity has its own newlinepositives, as well as negatives. The simple solution for ensuring the Network Security, as newlineit is a broader and larger domain when compared with System or Computer Security, is to newlinedesign and implement an Intrusion Detection System (IDS). IDS was first developed by newlineDorothy in 1983. newlineIDS are classified based on reaction, detection, location, analysis timing and newlinearchitecture; although common classification includes host based, network, hybrid and newlinedistributed. Anomaly Detection and Misuse Detection are two approaches that can be used newlinefor development of IDS, suitable for handling and detecting attacks in recent times. newlineDetection of an Attack in Anomaly based approach depends on the Anomalies , generated newlinewhen behaviour gets deviated from normal profile. Anomaly Detection is most widely used newlinein IDS, but it exhibits the bottleneck of high False Positive Rate. Anomaly Detection is newlineclassified into two categories, namely Signature based and Profile based. This paper newlineproposes Profile based System for Anomaly Detection comprising of two stages, viz., the newlinefirst step is to create a Model for characterizing the normal behavior of network traffic newlinethrough historical data, called Digital Signature of Network Segments using Flow Analysis newline(DSNSF) and the second step is detection of deviations in behavior with activation of newlinemulti-level Alarms. The proposed model works in a proactive manner, i.e., it automatically newlinedetects anomalies in network traffic without manual interference. newline

Description

Keywords

Citation

item.page.endorsement

item.page.review

item.page.supplemented

item.page.referenced