Skip to main content
Top

2016 | OriginalPaper | Chapter

Performance Analysis of Multiple Classifier System in DoS Attack Detection

Authors : Bayu Adhi Tama, Kyung Hyune Rhee

Published in: Information Security Applications

Publisher: Springer International Publishing

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

DoS attacks become a serious attack so as resource protection against this kind of attack is a compulsory task. The major challenge on designing detection scheme using machine learning technique is how to maximize detection rate with lower false alarm. In this paper, we employ and analyze the performance of multiple classifier system (MCS) to detect DoS attack. Several renowned base classifiers such as C4.5, SVM, and k-NN are combined using combination voting scheme and we compare the results with existing ensemble learning algorithms such as Bagging, Adaboost, and Rotation Forest. Based on the experiment using NSL-KDD dataset, MCS scheme has promising performance comparing to existing ensemble learner and single classifier.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literature
2.
go back to reference Aad, I., Hubaux, J.P., Knightly, E.W.: Impact of denial of service attacks on ad hoc networks. IEEE/ACM Trans. Netw. 16(4), 791–802 (2008)CrossRef Aad, I., Hubaux, J.P., Knightly, E.W.: Impact of denial of service attacks on ad hoc networks. IEEE/ACM Trans. Netw. 16(4), 791–802 (2008)CrossRef
3.
go back to reference Samara, G., Al-Salihy, W.A., Sures, R.: Security analysis of vehicular ad hoc nerworks (vanet). In: 2010 Second International Conference on Network Applications Protocols and Services (NETAPPS), pp. 55–60. IEEE (2010) Samara, G., Al-Salihy, W.A., Sures, R.: Security analysis of vehicular ad hoc nerworks (vanet). In: 2010 Second International Conference on Network Applications Protocols and Services (NETAPPS), pp. 55–60. IEEE (2010)
4.
go back to reference Bhuyan, M.H., Kashyap, H.J., Bhattacharyya, D.K., Kalita, J.: Detecting distributed denial of service attacks: Methods, tools, and future directions. Comput. J. 57, 537 (2013)CrossRef Bhuyan, M.H., Kashyap, H.J., Bhattacharyya, D.K., Kalita, J.: Detecting distributed denial of service attacks: Methods, tools, and future directions. Comput. J. 57, 537 (2013)CrossRef
5.
go back to reference Quinlan, J.R.: C4.5: Programs for Machine Learning. Elsevier, Amsterdam (2014) Quinlan, J.R.: C4.5: Programs for Machine Learning. Elsevier, Amsterdam (2014)
6.
go back to reference Cortes, C., Vapnik, V.: Support-vector networks. Mach. Learn. 20(3), 273–297 (1995)MATH Cortes, C., Vapnik, V.: Support-vector networks. Mach. Learn. 20(3), 273–297 (1995)MATH
7.
go back to reference Aha, D.W., Kibler, D., Albert, M.K.: Instance-based learning algorithms. Mach. Learn. 6(1), 37–66 (1991) Aha, D.W., Kibler, D., Albert, M.K.: Instance-based learning algorithms. Mach. Learn. 6(1), 37–66 (1991)
8.
go back to reference Kittler, J., Hatef, M., Duin, R.P., Matas, J.: On combining classifiers. IEEE Trans. Pattern Anal. Mach. Intell. 20(3), 226–239 (1998)CrossRef Kittler, J., Hatef, M., Duin, R.P., Matas, J.: On combining classifiers. IEEE Trans. Pattern Anal. Mach. Intell. 20(3), 226–239 (1998)CrossRef
9.
go back to reference Kuncheva, L.I.: Combining Pattern Classifiers: Methods and Algorithm. John Wiley & Sons, Chichester (2014)CrossRefMATH Kuncheva, L.I.: Combining Pattern Classifiers: Methods and Algorithm. John Wiley & Sons, Chichester (2014)CrossRefMATH
10.
go back to reference Wu, X., Kumar, V., Quinlan, J.R., Ghosh, J., Yang, Q., Motoda, H., McLachlan, G.J., Ng, A., Liu, B., Philip, S.Y., et al.: Top 10 algorithms in data mining. Knowl. Inf. Syst. 14(1), 1–37 (2008)CrossRef Wu, X., Kumar, V., Quinlan, J.R., Ghosh, J., Yang, Q., Motoda, H., McLachlan, G.J., Ng, A., Liu, B., Philip, S.Y., et al.: Top 10 algorithms in data mining. Knowl. Inf. Syst. 14(1), 1–37 (2008)CrossRef
12.
go back to reference Freund, Y., Schapire, R.E.: A decision-theoretic generalization of on-line learning and an application to boosting. J. Comput. Syst. Sci. 55(1), 119–139 (1997)MathSciNetCrossRefMATH Freund, Y., Schapire, R.E.: A decision-theoretic generalization of on-line learning and an application to boosting. J. Comput. Syst. Sci. 55(1), 119–139 (1997)MathSciNetCrossRefMATH
13.
go back to reference Rodriguez, J.J., Kuncheva, L.I., Alonso, C.J.: Rotation forest: A new classifier ensemble method. IEEE Trans. Pattern Anal. Mach. Intell. 28(10), 1619–1630 (2006)CrossRef Rodriguez, J.J., Kuncheva, L.I., Alonso, C.J.: Rotation forest: A new classifier ensemble method. IEEE Trans. Pattern Anal. Mach. Intell. 28(10), 1619–1630 (2006)CrossRef
14.
go back to reference Hall, M.A.: Correlation-based feature selection for machine learning. Ph.D. thesis, The University of Waikato (1999) Hall, M.A.: Correlation-based feature selection for machine learning. Ph.D. thesis, The University of Waikato (1999)
15.
go back to reference Bermejo, P., Gámez, J.A., Puerta, J.M.: Speeding up incremental wrapper feature subset selection with naive bayes classifier. Knowl.-Based Syst. 55, 140–147 (2014)CrossRef Bermejo, P., Gámez, J.A., Puerta, J.M.: Speeding up incremental wrapper feature subset selection with naive bayes classifier. Knowl.-Based Syst. 55, 140–147 (2014)CrossRef
16.
go back to reference Aliev, R.A., Fazlollahi, B., Aliev, R.R.: Soft Computing and its Applications in Business and Economics, vol. 157. Springer Science & Business Media, Heidelberg (2004)MATH Aliev, R.A., Fazlollahi, B., Aliev, R.R.: Soft Computing and its Applications in Business and Economics, vol. 157. Springer Science & Business Media, Heidelberg (2004)MATH
17.
go back to reference Toosi, A.N., Kahani, M.: A new approach to intrusion detection based on an evolutionary soft computing model using neuro-fuzzy classifiers. Comput. Commun. 30(10), 2201–2212 (2007)CrossRef Toosi, A.N., Kahani, M.: A new approach to intrusion detection based on an evolutionary soft computing model using neuro-fuzzy classifiers. Comput. Commun. 30(10), 2201–2212 (2007)CrossRef
19.
go back to reference Karimazad, R., Faraahi, A.: An anomaly-based method for DDoS attacks detection using RBF neural networks. In: 2011 International Conference on Network and Electronics Engineering, IPCSIT, vol. 11 (2011) Karimazad, R., Faraahi, A.: An anomaly-based method for DDoS attacks detection using RBF neural networks. In: 2011 International Conference on Network and Electronics Engineering, IPCSIT, vol. 11 (2011)
20.
go back to reference Kumar, P.A.R., Selvakumar, S.: Distributed denial of service attack detection using an ensemble of neural classifier. Comput. Commun. 34(11), 1328–1341 (2011)CrossRef Kumar, P.A.R., Selvakumar, S.: Distributed denial of service attack detection using an ensemble of neural classifier. Comput. Commun. 34(11), 1328–1341 (2011)CrossRef
21.
go back to reference Kumar, P.A.R., Selvakumar, S.: Detection of distributed denial of service attacks using an ensemble of adaptive and hybrid neuro-fuzzy systems. Comput. Commun. 36(3), 303–319 (2013)CrossRef Kumar, P.A.R., Selvakumar, S.: Detection of distributed denial of service attacks using an ensemble of adaptive and hybrid neuro-fuzzy systems. Comput. Commun. 36(3), 303–319 (2013)CrossRef
22.
go back to reference Ho, T.K., Hull, J.J., Srihari, S.N.: Decision combination in multiple classifier systems. IEEE Trans. Pattern Anal. Mach. Intell. 16(1), 66–75 (1994)CrossRef Ho, T.K., Hull, J.J., Srihari, S.N.: Decision combination in multiple classifier systems. IEEE Trans. Pattern Anal. Mach. Intell. 16(1), 66–75 (1994)CrossRef
23.
go back to reference Lachenbruch, P.A.: Multiple reading procedures: The performance of diagnostic tests. Stat. Med. 7(5), 549–557 (1988)CrossRef Lachenbruch, P.A.: Multiple reading procedures: The performance of diagnostic tests. Stat. Med. 7(5), 549–557 (1988)CrossRef
24.
go back to reference Kim, H., Kim, H., Moon, H., Ahn, H.: A weight-adjusted voting algorithm for ensembles of classifiers. J. Korean Stat. Soc. 40(4), 437–449 (2011)MathSciNetCrossRefMATH Kim, H., Kim, H., Moon, H., Ahn, H.: A weight-adjusted voting algorithm for ensembles of classifiers. J. Korean Stat. Soc. 40(4), 437–449 (2011)MathSciNetCrossRefMATH
25.
go back to reference Titterington, D., Murray, G., Murray, L., Spiegelhalter, D., Skene, A., Habbema, J., Gelpke, G.: Comparison of discrimination techniques applied to a complex data set of head injured patients. J. Roy. Stat. Soc.: Ser. A (Gen.) 144, 145–175 (1981)MathSciNetCrossRefMATH Titterington, D., Murray, G., Murray, L., Spiegelhalter, D., Skene, A., Habbema, J., Gelpke, G.: Comparison of discrimination techniques applied to a complex data set of head injured patients. J. Roy. Stat. Soc.: Ser. A (Gen.) 144, 145–175 (1981)MathSciNetCrossRefMATH
26.
go back to reference Raudys, Š.: Trainable fusion rules. I. large sample size case. Neural Netw. 19(10), 1506–1516 (2006)CrossRefMATH Raudys, Š.: Trainable fusion rules. I. large sample size case. Neural Netw. 19(10), 1506–1516 (2006)CrossRefMATH
27.
go back to reference Raudys, Š.: Trainable fusion rules. II. small sample-size effects. Neural Netw. 19(10), 1517–1527 (2006)CrossRefMATH Raudys, Š.: Trainable fusion rules. II. small sample-size effects. Neural Netw. 19(10), 1517–1527 (2006)CrossRefMATH
28.
go back to reference Hall, M., Frank, E., Holmes, G., Pfahringer, B., Reutemann, P., Witten, I.H.: The weka data mining software: An update. ACM SIGKDD Explor. Newslett. 11(1), 10–18 (2009)CrossRef Hall, M., Frank, E., Holmes, G., Pfahringer, B., Reutemann, P., Witten, I.H.: The weka data mining software: An update. ACM SIGKDD Explor. Newslett. 11(1), 10–18 (2009)CrossRef
29.
go back to reference Vapnik, V.: The Nature of Statistical Learning Theory. Springer Science & Business Media, Heidelberg (2000)CrossRefMATH Vapnik, V.: The Nature of Statistical Learning Theory. Springer Science & Business Media, Heidelberg (2000)CrossRefMATH
30.
go back to reference Chang, C.C., Lin, C.J.: LIBSVM: A library for support vector machines. ACM Trans. Intell. Syst. Technol. (TIST) 2(3), 27 (2011) Chang, C.C., Lin, C.J.: LIBSVM: A library for support vector machines. ACM Trans. Intell. Syst. Technol. (TIST) 2(3), 27 (2011)
31.
go back to reference Keerthi, S.S., Shevade, S.K., Bhattacharyya, C., Murthy, K.R.K.: Improvements to Platt’s SMO algorithm for SVM classifier design. Neural Comput. 13(3), 637–649 (2001)CrossRefMATH Keerthi, S.S., Shevade, S.K., Bhattacharyya, C., Murthy, K.R.K.: Improvements to Platt’s SMO algorithm for SVM classifier design. Neural Comput. 13(3), 637–649 (2001)CrossRefMATH
Metadata
Title
Performance Analysis of Multiple Classifier System in DoS Attack Detection
Authors
Bayu Adhi Tama
Kyung Hyune Rhee
Copyright Year
2016
Publisher
Springer International Publishing
DOI
https://doi.org/10.1007/978-3-319-31875-2_28

Premium Partner