期刊名称:International Journal of Computer Science and Network Security
印刷版ISSN:1738-7906
出版年度:2008
卷号:8
期号:4
页码:1-9
出版社:International Journal of Computer Science and Network Security
摘要:The main purpose of this paper is to propose a novel soft computing inference engine model for intrusion detection. Our approach is anomaly based and utilizes causal knowledge inference based fuzzy cognitive maps (FCM) and multiple self organizing maps (SOM). A set of parallel neural network classifiers (SOM) are used to do an initial recognition of the network traffic flow to detect abnormal behavior. The FCM incorporate to eliminate ambiguities of odd neurons and making final decisions. Initially, each neuron is mapped to its best matching unit in the self organizing map and then updated by the fuzzy cognitive map framework. This updating is achieved through the weights of the neighboring neurons. Based on the domain knowledge of network data (network packets) the SOM/FCM combination presents quantitative and qualitative matching correspondences which in turn reduce the number of suspicious neurons i.e. reduce the number of false alerts. This method work as a unique fuzzy clustering approach and we demonstrate its performance using DARPA 1999 network traffic data set.