2008 | OriginalPaper | Chapter
An Approach for Anomaly Intrusion Detection Based on Causal Knowledge-Driven Diagnosis and Direction
Authors : Mahmoud Jazzar, Aman Jantan
Published in: Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing
Publisher: Springer Berlin Heidelberg
Activate our intelligent search to find suitable subject content or patents.
Select sections of text to find matching patents with Artificial Intelligence. powered by
Select sections of text to find additional relevant content using AI-assisted search. powered by
Conventional knowledge acquisition methods such as semantic knowledge, production rules and question answering systems have been addressed to a variety of typical knowledge based systems. However, very limited causal knowledge based methods have been addressed to the problem of intrusion detection. In this paper, we propose an approach based on causal knowledge reasoning for anomaly intrusion detection. Fuzzy cognitive maps (FCM) are ideal causal knowledge acquiring tool with fuzzy signed graphs which can be presented as an associative single layer neural network. Using FCM, our methodology attempt to diagnose and direct network traffic data based on its relevance to attack or normal connections. By quantifying the causal inference process we can determine the attack detection and the severity of odd packets. As such packets with low causal relations to attacks can be dropped or ignored and/or packets with high causal relations to attacks are to be highlighted.