{"title":"Evolving Block-Based Neural Network and Field Programmable Gate Arrays for Host-Based Intrusion Detection System","authors":"Quang-Anh Tran, F. Jiang, Quang Minh Ha","doi":"10.1109/KSE.2012.31","DOIUrl":null,"url":null,"abstract":"In this paper, we design a prototype with hybrid software-enabled detection engine on the basis of an evolving block-based neural network (BBNN), and integrate it with a Field Programmable Gate Arrays (FPGA) board to enable a real-time host-based intrusion detection system (IDS). The established prototype can feed sequence of system calls obtained from a server directly into the BBNN based IDS. The structure and weights of BBNN are evolved by Genetic Algorithms. Experimental performance comparisons have been conducted against four major Support Vector Machines (SVMs) by carrying out leave-one-out cross validation. The results show that the improved BBNN outperforms other algorithms with respect to the classification and detection performances. The false alarm rate is successfully reduced as low as 2.22% while the detection rate 100% is still maintained. The running times of the proposed hardware based IDS versus other software based systems are also discussed.","PeriodicalId":122680,"journal":{"name":"2012 Fourth International Conference on Knowledge and Systems Engineering","volume":"63 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-08-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"15","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Fourth International Conference on Knowledge and Systems Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/KSE.2012.31","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 15
Abstract
In this paper, we design a prototype with hybrid software-enabled detection engine on the basis of an evolving block-based neural network (BBNN), and integrate it with a Field Programmable Gate Arrays (FPGA) board to enable a real-time host-based intrusion detection system (IDS). The established prototype can feed sequence of system calls obtained from a server directly into the BBNN based IDS. The structure and weights of BBNN are evolved by Genetic Algorithms. Experimental performance comparisons have been conducted against four major Support Vector Machines (SVMs) by carrying out leave-one-out cross validation. The results show that the improved BBNN outperforms other algorithms with respect to the classification and detection performances. The false alarm rate is successfully reduced as low as 2.22% while the detection rate 100% is still maintained. The running times of the proposed hardware based IDS versus other software based systems are also discussed.