Title :
A Real-Time NetFlow-based Intrusion Detection System with Improved BBNN and High-Frequency Field Programmable Gate Arrays
Author :
Tran, Quang Anh ; Jiang, Frank ; Hu, Jiankun
Author_Institution :
Fac. of Inf. Technol., Hanoi Univ., Hanoi, Vietnam
Abstract :
Future large-scale complex computing environments present challenges to the real-time intrusion detection systems (IDSs). In this paper, we design a prototype with hybrid software-enabled detection engine on the basis of our improved block-based neural network (BBNN), and integrate it with a high-frequency FPGA board to form a real-time intrusion detection system. The established prototype can seamlessly feed the large-scale NetFlow data obtained from Cisco routers directly into the improved BBNN based IDS. The corresponding BBNN structure and parameter settings have been improved and experimentally tested. Experimental performance comparisons have been conducted against four major schemes of Support Vector Machine (SVM) and Naive Bayes algorithm. The results show that the improved BBNN outperforms other algorithms with respect to the classification and detection performances. The false alarm rate is successfully reduced as low as 5.14% while the genuine detection rate 99.92% is still maintained.
Keywords :
Bayes methods; field programmable gate arrays; neural nets; pattern classification; protocols; support vector machines; telecommunication computing; telecommunication network routing; telecommunication security; BBNN; Cisco routers; IDS; SVM; block-based neural network; classification performances; detection performances; high-frequency FPGA board; high-frequency field programmable gate arrays; hybrid software-enabled detection engine; large-scale complex computing environments; naive Bayes algorithm; real-time NetFlow-based intrusion detection system; support vector machine; Artificial neural networks; Feature extraction; Field programmable gate arrays; Intrusion detection; Optimization; Real time systems; artificial neural network (ANN); field programmable gate arrays (FPGA); intrusion detection systems (IDSs); network security;
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
Conference_Location :
Liverpool
Print_ISBN :
978-1-4673-2172-3
DOI :
10.1109/TrustCom.2012.51