作者
Zeinab Heidarian, Naser Movahedinia, Neda Moghim, Payam Mahdinia
发表日期
2015/8/1
期刊
International Journal of Computer Network and Information Security
卷号
7
期号
9
页码范围
32
出版商
Modern Education and Computer Science Press
简介
As intrusion detection techniques based on malicious traffic signature are unable to detect unknown attacks, the methods derived from characterizing the behavior of the normal traffic are appropriate in case of detecting unseen intrusions. Based on such a technique, one class Support Vector Machine (SVM) is employed in this research to learn http regular traffic characteristics for anomaly detection. First, suitable features are extracted from the normal and abnormal http traffic; then the system is trained by the normal traffic samples. To detect anomaly, the actual traffic (including normal and abnormal packets) is compared to the deduced normal traffic. An anomaly alert is generated if any deviation from the regular traffic model is inferred. Examining the performance of the proposed algorithm using ISCX data set has delivered high accuracy of 89.25% and low false positive of 8.60% in detecting attacks on port 80. In this research, online step speed has reached to 77 times faster than CPU using GPU for feature extraction and OpenMp for parallel processing of packets.
引用总数
201620172018201920202021132322
学术搜索中的文章
Z Heidarian, N Movahedinia, N Moghim, P Mahdinia - International Journal of Computer Network and …, 2015