TY - JOUR
T1 - A LogitBoost-based Algorithm for Detecting Known and Unknown Web Attacks
AU - Kamarudin, Muhammad Hilmi
AU - Maple, Carsten
AU - Watson, Tim
AU - Sohrabi Safa, Nader
PY - 2017/11/3
Y1 - 2017/11/3
N2 - The rapid growth in the volume and importance of web communication throughout the Internet has heightened the need for better security protection. Security experts, when protecting systems, maintain a database featuring signatures of a large number of attacks to assist with attack detection. However, used in isolation, this can limit the capability of the system as it is only able to recognise known attacks. To overcome the problem, we propose an anomaly based intrusion detection system using an ensemble classification approach to detect unknown attacks on web servers. The process involves removing irrelevant and redundant features utilising a filter and wrapper selection procedure. Logitboost (LB) is then employed together with Random Forests (RF) as a weak classifier. The proposed ensemble technique was evaluated with some artificial datasets namely NSL-KDD, an improved version of the old KDD Cup from 1999, and the recently published UNSW-NB15 dataset. The experimental results show that our approach demonstrates superiority, in terms of accuracy and detection rate over the traditional approaches, whilst preserving low false rejection rates.
AB - The rapid growth in the volume and importance of web communication throughout the Internet has heightened the need for better security protection. Security experts, when protecting systems, maintain a database featuring signatures of a large number of attacks to assist with attack detection. However, used in isolation, this can limit the capability of the system as it is only able to recognise known attacks. To overcome the problem, we propose an anomaly based intrusion detection system using an ensemble classification approach to detect unknown attacks on web servers. The process involves removing irrelevant and redundant features utilising a filter and wrapper selection procedure. Logitboost (LB) is then employed together with Random Forests (RF) as a weak classifier. The proposed ensemble technique was evaluated with some artificial datasets namely NSL-KDD, an improved version of the old KDD Cup from 1999, and the recently published UNSW-NB15 dataset. The experimental results show that our approach demonstrates superiority, in terms of accuracy and detection rate over the traditional approaches, whilst preserving low false rejection rates.
UR - https://www.scopus.com/pages/publications/85033671788
U2 - 10.1109/ACCESS.2017.2766844
DO - 10.1109/ACCESS.2017.2766844
M3 - Article
SN - 2169-3536
VL - 5
SP - 26190
EP - 26200
JO - IEEE Access
JF - IEEE Access
ER -