A Novel Approach to Optimize the Performance of Network Based IDS Using Enhanced EBPA and Ant Colony Optimization
Loading...
Date
item.page.authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Due to the recent developments and revolutions in the field of Technology and
newlineInternet at a rapid pace, the domain of Computer and Network Security has been of keen
newlineinterest to the Researchers, Developers and Hackers. Due to these developments in the
newlinedomain of Internet, Hackers and Attackers got an opportunity to access the Resources,
newlineServices and Data over Internet through unfair means using the bottlenecks of these
newlinedevelopments, as nothing is 100 % perfect in this world; each and every entity has its own
newlinepositives, as well as negatives. The simple solution for ensuring the Network Security, as
newlineit is a broader and larger domain when compared with System or Computer Security, is to
newlinedesign and implement an Intrusion Detection System (IDS). IDS was first developed by
newlineDorothy in 1983.
newlineIDS are classified based on reaction, detection, location, analysis timing and
newlinearchitecture; although common classification includes host based, network, hybrid and
newlinedistributed. Anomaly Detection and Misuse Detection are two approaches that can be used
newlinefor development of IDS, suitable for handling and detecting attacks in recent times.
newlineDetection of an Attack in Anomaly based approach depends on the Anomalies , generated
newlinewhen behaviour gets deviated from normal profile. Anomaly Detection is most widely used
newlinein IDS, but it exhibits the bottleneck of high False Positive Rate. Anomaly Detection is
newlineclassified into two categories, namely Signature based and Profile based. This paper
newlineproposes Profile based System for Anomaly Detection comprising of two stages, viz., the
newlinefirst step is to create a Model for characterizing the normal behavior of network traffic
newlinethrough historical data, called Digital Signature of Network Segments using Flow Analysis
newline(DSNSF) and the second step is detection of deviations in behavior with activation of
newlinemulti-level Alarms. The proposed model works in a proactive manner, i.e., it automatically
newlinedetects anomalies in network traffic without manual interference.
newline