[論文レビュー] Intrusion Detection In Mobile Ad Hoc Networks Using GA Based Feature Selection
本稿では、不正検出のための遺伝的アルゴリズム(GA)に基づく特徴選択手法を、ベイジアンネットワークを用いて特徴の関連性を最適化し、検出精度を向上させることで、モバイルアドホックネットワーク(MANETs)に適用する手法を提案している。この手法は冗長な特徴を低減し、マコフブラケットに基づく選択と比較して、より高い検出率と低い誤検出率を達成している。
Mobile ad hoc networking (MANET) has become an exciting and important technology in recent years because of the rapid proliferation of wireless devices. MANETs are highly vulnerable to attacks due to the open medium, dynamically changing network topology and lack of centralized monitoring point. It is important to search new architecture and mechanisms to protect the wireless networks and mobile computing application. IDS analyze the network activities by means of audit data and use patterns of well-known attacks or normal profile to detect potential attacks. There are two methods to analyze: misuse detection and anomaly detection. Misuse detection is not effective against unknown attacks and therefore, anomaly detection method is used. In this approach, the audit data is collected from each mobile node after simulating the attack and compared with the normal behavior of the system. If there is any deviation from normal behavior then the event is considered as an attack. Some of the features of collected audit data may be redundant or contribute little to the detection process. So it is essential to select the important features to increase the detection rate. This paper focuses on implementing two feature selection methods namely, markov blanket discovery and genetic algorithm. In genetic algorithm, bayesian network is constructed over the collected features and fitness function is calculated. Based on the fitness value the features are selected. Markov blanket discovery also uses bayesian network and the features are selected depending on the minimum description length. During the evaluation phase, the performances of both approaches are compared based on detection rate and false alarm rate.
研究の動機と目的
- モバイルアドホックネットワーク(MANETs)がオープンな媒体と動的トポロジを持つため、攻撃に対して脆弱であるという問題に対処する。
- 監査データ内の冗長または関連のない特徴を低減することで、不正検出システム(IDS)の性能を向上させる。
- ベイジアンネットワークフレームワーク内での2つの特徴選択手法(遺伝的アルゴリズム(GA)とマコフブラケットの同定)の有効性を比較する。
- 異常ベースの不正検出における検出率を最適化し、誤検出率を最小限に抑える。
提案手法
- 正常および異常なネットワーク動作をモデル化するため、さまざまな攻撃をシミュレートした後にモバイルノードから監査データを収集する。
- 収集された特徴の上にベイジアンネットワークを構築し、特徴間の確率的依存関係をモデル化する。
- ベイジアンネットワークから導出されたフィットネス関数を最大化するように、遺伝的アルゴリズム(GA)を用いて最適な特徴サブセットを探索する。
- マコフブラケットの同定において、最小記述長(MDL)原理を用いて予測精度を保持する最も関連性の高い特徴を同定する。
- 検出率と誤検出率を性能指標として、両手法を評価する。
- 異常検出におけるGAベースおよびマコフブラケットベースの特徴選択の検出性能と効率性を比較する。
実験結果
リサーチクエスチョン
- RQ1遺伝的アルゴリズムベースの特徴選択は、従来の手法と比較して、MANETにおける不正検出性能をどのように向上させるか?
- RQ2GAベースとマコフブラケットベースの特徴選択は、誤検出率の低減と検出率の向上において、それぞれどの程度の有効性を示すか?
- RQ3どの特徴サブセット選択手法が、MANETにおける異常検出の監査データの予測力をよりよく保持するか?
- RQ4冗長または関連のない特徴は、モバイルアドホックネットワークにおける不正検出システムの性能をどの程度劣化させるか?
主な発見
- 遺伝的アルゴリズムベースの特徴選択手法は、マコフブラケット同定手法よりも高い検出率を達成した。
- GAベースの手法は、実際の攻撃をより正確に特定していることを示唆する、低い誤検出率となった。
- ベイジアンネットワークを用いた特徴選択は、検出精度を損なうことなく監査データの次元を顕著に低減した。
- マコフブラケット同定手法は効果的ではあるが、不正検出のためのフィットネス関数最適化において、やや非効率であった。
- 両手法とも冗長な特徴の影響を低減したが、評価においてGAベースのアプローチが優れた全体的なパフォーマンスを示した。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。