By Topic

A novel adaptive intrusion detection approach based on comparison of neural networks and idiotypic networks

Sign In

Cookies must be enabled to login.After enabling cookies , please use refresh or reload or ctrl+f5 on the browser for the login options.

Formats Non-Member Member
$31 $13
Learn how you can qualify for the best price for this item!
Become an IEEE Member or Subscribe to
IEEE Xplore for exclusive pricing!
close button

puzzle piece

IEEE membership options for an individual and IEEE Xplore subscriptions for an organization offer the most affordable access to essential journal articles, conference papers, standards, eBooks, and eLearning courses.

Learn more about:

IEEE membership

IEEE Xplore subscriptions

3 Author(s)
Linhui Zhao ; Sch. of Mechatron., Beijing Union Univ., Beijing, China ; Xin Fang ; Yaping Dai

Although neural networks and idiotypic networks are similar in functions, they are different in many aspects. This paper compares them in topological structures, initializing ways, learning methods, et al. Based on the comparison and combined with pattern recognition technology, this paper proposes a novel adaptive intrusion detection approach using idiotypic networks. Additionally, the approach is compared with detection approach using neural networks. Idiotypic networks' memory and learning abilities, especially their dynamic adjustable ability enable them superior to neural networks in the application for intrusion detection. This paper presents a new detection algorithm according to immune response principles and a new multimutation pattern idiotypic network model to implement the detection algorithm. By utilizing some immune principles, the proposed approach can overcome problems existing in detection approaches based on neural networks. Firstly, idiotypic networks can adjust automatically with presenting of antigens, making new features fused into networks continuously. Thus, this approach needs not to be updated periodically. Secondly, the trained network model can still be changed to learn new features of attacks, so the performance of detecting unknown attacks is improved. Thirdly, clone expansion of antibodies is suppressed by idiotypic effects, thus false positive rate is decreased. Experiments are carried out on Fisher Iris dataset and KDD-CUP-99 database to verify the performance of this adaptive detection approach. Compared with the detection approach based on a multilayer perception network, the false positive rate is decreased and the detection accuracy of unknown attacks is increased.

Published in:

Nonlinear Dynamics and Synchronization, 2009. INDS '09. 2nd International Workshop on

Date of Conference:

20-21 July 2009