Affiliation:
1. Department of Statistics, Institut Teknologi Sepuluh Nopember, Surabaya 60111, Indonesia
2. Department of Mathematical Sciences, Universiti Teknologi Malaysia, Johor Bahru 81310, Malaysia
Abstract
Intrusion detection systems (IDS) are crucial in safeguarding network security by identifying unauthorized access attempts through various techniques. Statistical Process Control (SPC), particularly Hotelling’s T2 control charts, is noted for monitoring network traffic against known attack patterns or anomaly detection. This research advances the domain by incorporating robust statistical estimators—namely, the Fast-MCD and MRCD (Minimum Regularized Covariance Determinant) estimators—into bootstrap-enhanced Hotelling’s T2 control charts. These enhanced charts aim to strengthen detection accuracy by offering improved resistance to outlier contamination, a prevalent challenge in intrusion detection. The methodology emphasizes the MRCD estimator’s robustness in overcoming the limitations of traditional T2 charts, especially in environments with a high incidence of outliers. Applying the proposed bootstrap-based robust T2 charts to the UNSW-NB15 dataset illustrates a marked enhancement in intrusion detection performance. Results indicate superior performance of the proposed method over conventional T2 and Fast-MCD-based T2 charts in detection accuracy, even in varied levels of outlier contamination. Despite increasing execution time, the precision and reliability in detecting intrusions present a justified trade-off. The findings underscore the significant potential of integrating robust statistical methods to enhance IDS effectiveness.
Funder
Institut Teknologi Sepuluh Nopember
Reference48 articles.
1. Bace, R., and Mell, P. (2001). NIST Special Publication on Intrusion Detection Systems, National Institute of Standards and Technology. Nist Special Publication.
2. A framework for constructing features and models for intrusion detection systems;Lee;ACM Trans. Inf. Syst. Secur.,2000
3. Wu, G., and Huang, Y. (2009, January 15–17). Design of a New Intrusion Detection System Based on Database. Proceedings of the 2009 International Conference on Signal Processing Systems, Singapore.
4. Park, Y. (2005). A Statistical Process Control Approach for Network Intrusion Detection, Georgia Insitute of Technology.
5. Some applications of statistical methods to the analysis of physical and engineering data;Shewhart;Bell Syst. Tech. J.,1924