تجاوز إلى المحتوى الرئيسي
User Image

Abdelouahid Derhab

Associate Professor

Faculty member

علوم الحاسب والمعلومات
Address: Office No. 4, Center of Excellence in Information Assurance (CoEIA), Building No. 31, King Saud University
المنشورات
مقال فى مجلة
2014

Multivariate correlation analysis and geometric linear similarity for real‐time intrusion detection systems

Derhab, Abdelouahid, Abdelghani Bouras . 2014

Accepted

In this paper, we propose an intrusion detection system (IDS) based on four approaches: (i) statistical-based IDS to reduce detection time; (ii) intertwining data acquisition phase and data preprocessing phase to ensure real-time detection; (iii) geometric linear similarity measure that improves detection accuracy compared with existing measures; and (iv) multivariate correlation analysis that extracts a subset of strongly correlated features to construct a normal behavioral graph. Based on this graph, we derive the normal profile composed of high-level features. We use NSL-KDD dataset to analyze and evaluate the efficiency of the proposed IDS at detecting denial-of-service (DOS) attacks. Experimental results show that the proposed IDS can achieve good results in terms of detection rate and false positive rate. For some DOS attacks, 100% detection rate is achieved with 1.55% false positive. We also use KDD99 dataset to compare the proposed IDS with two statistical-based methods and some data mining and machine learning-based methods. Comparison study shows that the proposed IDS achieves the best tradeoff between detection rate (99.76%) and false positive rate (0.6%). It also requires just a few microseconds to classify the connection as normal or attack with low CPU usage and low memory consumption.

مجلة/صحيفة
Security and Communication Networks
مزيد من المنشورات
publications

In this paper, we inspire from two analogies: the warfare kill zone and the airport check-in system, to design and deploy a new line in the defense-in-depth strategy, called the third line.

بواسطة Abdelouahid, Kashif Saleem, Ahmed Youssef Derhab
2014
publications

In this paper, we adopt the divide-and-conquer strategy to propose a lightweight design for an intrusion detection system in wireless sensor networks, lIghtweiGht aNomaly-based Intrusion deTection…

بواسطة Abdelouahid, Abdelghani Bouras Derhab
2014
publications

In this paper, we propose an intrusion detection system (IDS) based on four approaches: (i) statistical-based IDS to reduce detection time; (ii) intertwining data acquisition phase and data…

بواسطة Abdelouahid, Abdelghani Bouras Derhab
2014