. The imperfection of existing intrusion detection methods, as well as the changing nature of malicious actions by the attacker, make computer systems unsafe, therefore it is important to identify new types of attacks and respond to them on time. The developed hybrid scheme for detecting and classifying network attacks based on a combination of adaptive classifiers. The study proposed a generalized scheme for combining classifiers to detect network attacks. Based on it, a software tool has been developed that allows you to analyze network traffic for the presence of abnormal network activity. To reduce the number of features used, it is proposed to use the method of principal components. The main feature of the proposed approach is a multilevel analysis of network traffic, as well as the use of various adaptive modules in the attack detection process. Computational experiments were carried out on two open data sets using various methods of combining classifiers. The developed modules can be used to process data received from sensors of the information and security events management system.
Paper
Full text
Development of a network attack detection system based on hybrid neuro-fuzzy algorithms
Semantic Scholar · Computer Science · 2020
Abstract
. The imperfection of existing intrusion detection methods, as well as the changing nature of malicious actions by the attacker, make computer systems unsafe, therefore it is important to identify new types of attacks and respond to them on time. The developed hybrid scheme for detecting and classifying network attacks based on a combination of adaptive classifiers. The study proposed a generalized scheme for combining classifiers to detect network attacks. Based on it, a software tool has been developed that allows you to analyze network traffic for the presence of abnormal network activity. To reduce the number of features used, it is proposed to use the method of principal components. The main feature of the proposed approach is a multilevel analysis of network traffic, as well as the use of various adaptive modules in the attack detection process. Computational experiments were carried out on two open data sets using various methods of combining classifiers. The developed modules can be used to process data received from sensors of the information and security events management system.