Host based intrusion detection system with combined CNN/RNN model.
View/ Open
Date
2018Author
Chawla, Ashima
Lee, Brian
Fallon, Sheila
Jacob, Paul
Metadata
Show full item recordAbstract
Cyber security has become one of the most challenging as-
pects of modern world digital technology and it has become imperative
to minimize and possibly avoid the impact of cybercrimes. Host based
intrusion detection systems help to protect systems from various kinds of
malicious cyber attacks. One approach is to determine normal behaviour
of a system based on sequences of system calls made by processes in
the system [1]. This paper describes a computational e cient anomaly
based intrusion detection system based on Recurrent Neural Networks.
Using Gated Recurrent Units rather than the normal LSTM networks it
is possible to obtain a set of comparable results with reduced training
times. The incorporation of stacked CNNs with GRUs leads to improved
anomaly IDS. Intrusion Detection is based on determining the prob-
ability of a particular call sequence occurring from a language model
trained on normal call sequences from the ADFA Data set of system call
traces [2]. Sequences with a low probability of occurring are class ed as an anomaly.
Collections
The following license files are associated with this item: