Semi-supervised multi-layered clustering model for intrusion detection

dc.contributor.authorAl-Jarrah, Omar Y.
dc.contributor.authorAl-Hammdi, Yousof
dc.contributor.authorYoo, Paul D.
dc.contributor.authorMuhaidat, Sami
dc.contributor.authorAl-Qutayri, Mahmoud
dc.date.accessioned2017-11-23T17:16:11Z
dc.date.available2017-11-23T17:16:11Z
dc.date.issued2017-09-22
dc.description.abstractA Machine Learning (ML) -based Intrusion Detection and Prevention System (IDPS) requires a large amount of labeled up-to-date training data, to effectively detect intrusions and generalize well to novel attacks. However, labeling of data is costly and becomes infeasible when dealing with big data, such as those generated by IoT (Internet of Things) -based applications. To this effect, building a ML model that learns from non- or partially-labeled data is of critical importance. This paper proposes a novel Semi-supervised Multi-Layered Clustering Model (SMLC) for network intrusion detection and prevention tasks. The SMLC has the capability to learn from partially labeled data while achieving a comparable detection performance to supervised ML-based IDPS. The performance of the SMLC is compared with well-known supervised ensemble ML models, namely, RandomForest, Bagging, and AdaboostM1 and a semi-supervised model (i.e., tri-training) on a benchmark network intrusion dataset, the Kyoto 2006+. Experimental results show that the SMLC outperforms all other models and can achieve better detection accuracy using only 20% labeled instances of the training data.en_UK
dc.identifier.citationAl-Jarrah OY, Al-Hammdi Y, Yoo PD, et al., (2017) Semi-supervised multi-layered clustering model for intrusion detection. Digital Communications and Networks, Volume 4, Issue 4, November 2018, pp. 277-286en_UK
dc.identifier.issn2352-8648
dc.identifier.urihttps://doi.org/10.1016/j.dcan.2017.09.00
dc.identifier.urihttp://dspace.lib.cranfield.ac.uk/handle/1826/12735
dc.publisherElsevieren_UK
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/
dc.titleSemi-supervised multi-layered clustering model for intrusion detectionen_UK
dc.typeArticleen_UK

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Semi-supervised_mulit-layed_clustering_model-2018.pdf
Size:
741.32 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.79 KB
Format:
Item-specific license agreed upon to submission
Description: