Top Banner
Immune-inspired Network Intrusion Detection System (i-NIDS) 1 Next Generation Intelligent Networks Research Center National University of Computer & Emerging Sciences Islamabad, Pakistan http://www.nexginrc.org M. Zubair Shafiq 1 , Syed Ali Khayam 2 , Muddassar Farooq 1 GECCO HUMIES - 2008 2 School of Electrical Engineering & Computer Sciences National University of Sciences & Technology Rawalpindi, Pakistan http://wisnet.niit.edu.pk
12

Immune-inspired Network Intrusion Detection System ( i -NIDS)

Jan 04, 2016

Download

Documents

rana-phelps

GECCO HUMIES - 2008. Immune-inspired Network Intrusion Detection System ( i -NIDS). M. Zubair Shafiq 1 , Syed Ali Khayam 2 , Muddassar Farooq 1. 1 Next Generation Intelligent Networks Research Center National University of Computer & Emerging Sciences Islamabad, Pakistan - PowerPoint PPT Presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

Immune-inspired Network Intrusion Detection System

(i-NIDS)

1 Next Generation Intelligent Networks Research CenterNational University of Computer & Emerging Sciences

Islamabad, Pakistanhttp://www.nexginrc.org

M. Zubair Shafiq1, Syed Ali Khayam2, Muddassar Farooq1

GECCO HUMIES - 2008

2 School of Electrical Engineering & Computer SciencesNational University of Sciences & Technology

Rawalpindi, Pakistanhttp://wisnet.niit.edu.pk

Page 2: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

2

Introduction

Simple Human competitive

Human^ machine

competitive

Page 3: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

3

Unfortunately, most computer viruses are not so courteous!

Page 4: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

4

Threat numbers show the story of what’s happening?

Page 5: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

5

These are Commercial Software…

Page 6: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

6

Motivation for current work

Page 7: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

7

Network Traffic Stream

Intelligent Statistical Features1.Memory of Markov Chain2.Multi resolution session rate3.Entropy of IP address4.Divergence of port distribution

Immune inspired Network Intrusion Detection System

Alarm Output

Adaptive Immune System/Innate Immune System1.Negative Selection2.Dendritic Cell Algorithm

Page 8: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

8

Human^machine Competitive Results

Detector TP rate (%) FP rate (%)[Classical Bio-inspired Detector]

Naïve RVNS53.5 7.9

[Classical Bio-inspired Detector]Naïve DCA

61.6 5.8

[State-of-the-art Statistical Detector] Rate Limiting

84.4 1.4

[State-of-the-art Statistical Detector] Maximum Entropy

83.1 4.2

[Immune inspired NIDS] i-RVNS

94.9 0.2

[Immune inspired NIDS] i-DCA

94.6 0.1

Page 9: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

9

Engineered System

Network Protocol Stack

(Client Machine)

PBTSApplication

Layer

PBTSTransport Layer

PBTSNetwork Layer

PBTSDatalink Layer

WBFCApplication

Layer

WBFCTransport Layer

WBFCNetwork Layer

WBFCDatalink Layer

BCMApplication

Layer

BCMTransport Layer

BCMNetwork Layer

BCMDatalink Layer

PBSP-App Features-App

PBSP-Trans Features-Trans

PBSP-Net Features-Net

PBSP-DL Features-DL

Decision Feedback

Decision Feedback

Decision Feedback

Traffic

Traffic

Traffic

Traffic

Decision Feedback

Keys : PBTS : Policy Based Traffic SnifferWBFC : Window Based Feature ComputersBCM : Binary Classifier Module

Complete version will be ready in 1 year time; free download

Patent pending

US$200,000 grant to develop the final product from the National ICT R&D fund, Government of Pakistan

Page 10: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

10

Why the best? In a nutshell…

Page 11: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

11

Publications

A Comparative Study of Fuzzy Inference Systems, Neural Networks and Adaptive Neuro Fuzzy Inference Systems for Portscan Detection

M. Zubair Shafiq, Muddassar Farooq and Syed Ali Khayam

In M. Giacobini et al.(Eds.), Proceedings of Applications of Evolutionary Computing, EvoWorkshops 2007 (EuroGP-EvoCoMnet), Volume 4974 of Lecture Notes in Computer Science, pp. 48–57, Springer Verlag, Napoli, Italy, March,2008. (BEST PAPER NOMINATION)

Improving the Accuracy of Immune-inspired Malware Detectors by using Intelligent Features

M. Zubair Shafiq, Syed Ali Khayam and Muddassar Farooq

In Genetic and Evolutionary Conference (GECCO), July, 2008, Atlanta, USA.

Page 12: Immune-inspired Network Intrusion Detection System  ( i -NIDS)

12