A comparison of neural projection techniques applied to intrusion detection systems

  • Authors:
  • Álvaro Herrero;Emilio Corchado;Paolo Gastaldo;Rodolfo Zunino

  • Affiliations:
  • Civil Engineering Department, University of Burgos, Burgos, Spain;Civil Engineering Department, University of Burgos, Burgos, Spain;Department of Biophysical and Electronic Engineering, Genoa University, Genoa, Italy;Department of Biophysical and Electronic Engineering, Genoa University, Genoa, Italy

  • Venue:
  • IWANN'07 Proceedings of the 9th international work conference on Artificial neural networks
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper reviews one nonlinear and two linear projection architectures, in the context of a comparative study, which are used as either alternative or complementary tools in the identification and analysis of anomalous situations by Intrusion Detection Systems (IDSs). Three neural projection models are empirically compared, using real traffic data sets in an IDS framework. The specific multivariate data analysis techniques that drive these models are able to identify different factors or components by studying higher order statistics - variance and kurtosis - in order to display the most interesting projections or dimensions. Our research describes how a network manager is able to diagnose anomalous behaviour in data traffic through visual projection of network traffic. We also emphasize the importance of the time-dependent variable in the application of these projection methods.