Improvement in intrusion detection with advances in sensor fusion

Thomas, C. ; Balakrishnan, N. (2009) Improvement in intrusion detection with advances in sensor fusion IEEE Transactions on Information Forensics and Security, 4 (3). pp. 542-551. ISSN 1556-6013

[img]
Preview
PDF - Author Version
227kB

Official URL: http://ieeexplore.ieee.org/xpl/freeabs_all.jsp?arn...

Related URL: http://dx.doi.org/10.1109/TIFS.2009.2026954

Abstract

Various intrusion detection systems (IDSs) reported in the literature have shown distinct preferences for detecting a certain class of attack with improved accuracy, while performing moderately on the other classes. In view of the enormous computing power available in the present-day processors, deploying multiple IDSs in the same network to obtain best-of-breed solutions has been attempted earlier. The paper presented here addresses the problem of optimizing the performance of IDSs using sensor fusion with multiple sensors. The trade-off between the detection rate and false alarms with multiple sensors is highlighted. It is illustrated that the performance of the detector is better when the fusion threshold is determined according to the Chebyshev inequality. In the proposed data-dependent decision (DD) fusion method, the performance optimization of individual IDSs is first addressed. A neural network supervised learner has been designed to determine the weights of individual IDSs depending on their reliability in detecting a certain attack. The final stage of this DD fusion architecture is a sensor fusion unit which does the weighted aggregation in order to make an appropriate decision. This paper theoretically models the fusion of IDSs for the purpose of demonstrating the improvement in performance, supplemented with the empirical evaluation.

Item Type:Article
Source:Copyright of this article belongs to IEEE.
ID Code:64430
Deposited On:10 Oct 2011 07:36
Last Modified:18 May 2016 12:51

Repository Staff Only: item control page