- Book Chapter
8
- 10.1016/b978-0-12-416688-2.00005-2
Chapter 5 - Intrusion Prevention and Detection Systems
- Jan 01, 2013
- Managing Information Security
- Christopher Day
Chapter 5 - Intrusion Prevention and Detection Systems
LoRaWAN enables low-power, long-range IoT connectivity, but its security testing suffers from a lack of accessible, labeled datasets. Anomaly and intrusion detection methods require realistic communication logs, yet real-world traffic is limited by privacy regulations and proprietary constraints. This paper introduces a conceptual framework that integrates Large Language Models (LLMs) with deterministic protocol construction to generate synthetic, privacy-safe logs. This multi-stage process couples cryptographic precision with LLM adaptability to produce diverse, compliant data for Intrusion Detection System (IDS) evaluation. We outline the framework, validation methodology, and preliminary Proof of Concept, providing a foundation for reproducible and ethical IoT security testing.
Chapter 5 - Intrusion Prevention and Detection Systems
Chapter 5 - Intrusion Prevention and Detection Systems
Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Read moreGenerative AI in cybersecurity: A comprehensive review of LLM applications and vulnerabilities
Generative AI in cybersecurity: A comprehensive review of LLM applications and vulnerabilities
Hybrid bagging and boosting with SHAP based feature selection for enhanced predictive modeling in intrusion detection systems
The novelty and growing sophistication of cyber threats mean that high accuracy and interpretable machine learning models are needed more than ever before for Intrusion Detection and Prevention Systems. This study aims to solve this challenge by applying Explainable AI techniques, including Shapley Additive explanations feature selection, to improve model performance, robustness, and transparency. The method systematically employs different classifiers and proposes a new hybrid method called Hybrid Bagging-Boosting and Boosting on Residuals. Then, performance is taken in four steps: the multistep evaluation of hybrid ensemble learning methods for binary classification and fine-tuning of performance; feature selection using Shapley Additive explanations values retraining the hybrid model for better performance and reducing overfitting; the generalization of the proposed model for multiclass classification; and the evaluation using standard information metrics such as accuracy, precision, recall, and F1-score. Key results indicate that the proposed methods outperform state-of-the-art algorithms, achieving a peak accuracy of 98.47% and an F1 score of 96.19%. These improvements stem from advanced feature selection and resampling techniques, enhancing model accuracy and balancing precision and recall. Integrating Shapley Additive explanations-based feature selection with hybrid ensemble methods significantly boosts the predictive and explanatory power of Intrusion Detection and Prevention Systems, addressing common pitfalls in traditional cybersecurity models. This study paves the way for further research on statistical innovations to enhance Intrusion Detection and Prevention Systems performance.
Read moreDeveloping an Intelligent Intrusion Detection and Prevention System against Web Application Malware
Malware authors are continuously developing crime toolkits. This has led to the situation of zero-day attacks, where malware harm computer systems despite the protection from existing Intrusion Detection Systems (IDSs). We propose an Intelligent Intrusion Detection and Prevention System (IIDPS) approach that combines the Signature based Intrusion Detection system (SIDS), Anomaly based Intrusion Detection System (AIDS) and Response Intrusion Detection System (RIDS). We used a risk assessment approach to determine an appropriate response action against each attack event. We also demonstrated the IIDPS make the detection and prevention of malware more effective.
Read moreNeural Networks for Intrusion Detection
This paper presents Intrusion Detection Systems (IDS), Intrusion Detection and Prevention Systems (IDPS) and their classification emphasizing on the use of neural networks in IDS. Contemporary IDS usually include both signature verification and anomaly detection approaches realized by rule-based expert system and statistical module correspondingly. Neural networks may be used mainly as additional module to the statistical module to better recognize the user behavior. User behavior may be represented as frequency pattern of users command history. The paper presents an example of user profile vector for Unix-based platforms.
Read moreIntrusion Detection Based on Active Networks
The network security is getting more important due to the wide-spread computer viruses and increasing network attacks. Nowadays, more and more security mechanisms, such as firewalls and intrusion detection systems (IDS), are introduced to protect the network from malicious attacks. This paper proposes an agent and service based intrusion detection and response system for active network. In contrast to a traditional passive network, an active network gives the nodes programmable ability to exercise various active network technologies. The intrusion response, service deployment, and service update mechanisms are centered on this technology. The proposed model of intrusion detection and response system (IDRS) catches network attacks and responses to stop the attacks at the first time to reduce the damage. Detecting, reporting, and responding capabilities are all embedded and integrated in the proposed system. A prototype system is developed using a novel data mining technology (the support vector machine) to enhance the detection function. In addition, several experiments were conducted to verify the system and results showed that the system was able to effectively identify the intrusions and respond promptly. Experiments also showed that the support vector machine outperforms the competitive neural networks in identifying the intrusions.
Read moreLarge Language Models in Urban Planning: A Systematic Review and Conceptual Framework
The rapid advancement of large language models (LLMs) has sparked growing interest in their potential applications within urban planning. These models offer novel capabilities in natural language processing tasks, potentially providing advanced support across various aspects of urban planning. Despite the promises, little is known about how and to what extent LLMs have been applied in the planning literature. This study addresses this gap by conducting a comprehensive literature review using the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) methodology. The review depicts five key domains where LLMs are being applied in urban planning: (a) planning and management; (b) public services and participation; (c) transportation and urban mobility; (d) environmental monitoring and sustainability; and (e) urban design and architecture. Additionally, the review identifies four essential characteristics that LLMs should possess to be effective in urban planning: (a) professionalism; (b) inclusivity; (c) trustworthiness; and (e) convenience. Considering the findings, a conceptual framework is developed that illustrates how these characteristics enhance the flexibility and effectiveness of LLMs in supporting urban planning tasks. This framework offers a theoretical foundation for urban planners to effectively integrate LLMs into practice and provides a roadmap for future research and technological innovations in the application of LLMs within urban environments.
Read moreDetecting Computer Network Anomaly with Data Mining Technology
With the rapid development of machine learning and Internet technology, the combination of the two methods is well appreciated recently.An anomaly and intrusion detection system is a mechanism that monitors network or system activities for malicious activities.Intrusion detection and prevention systems are primarily focused on identifying possible incidents, logging information about them and reporting attempts.As far as other usages of Intrusion detection and prevention systems are concerned, such as identifying problems with security policies and deterring individuals from violating security policies.Anomaly detection systems are becoming an important addition to the security infrastructure of nearly every organization.In this paper, we propose a novel mechanism for real-world traffic and research there cases with theoretical analysis.
Read moreSecurity in Artificial Systems
In the context of a computer system, computer security is the prevention of an illicit action against the system. For this purpose, computer security must determine the difference between normal and harmful activities. These activities can come from outside or from inside the system to be protected. In a similar manner, the role of the Human Immune System (HIS) is to detect and defend against harm. This similarity has inspired approaches in the area of computer security, including the use of immune-based approaches to build Intrusion Detection and Response Systems (IDRSs). As a concrete example, this chapter introduces a new approach for Intrusion Detection (ID) and Intrusion Response (IR) to build a completely distributed and decentralised IDRS for use in computer networks. This approach is called Intrusion Detection and Response extended with Agent Mobility, or IDReAM for short. IDReAM combines Mobile Agents (MAs) with two self-organising paradigms inspired by natural life systems. The Intrusion Detection System (IDS) is inspired by the metaphor of the immune system that protects the human body from external threats. Specialised cells of the immune system, called the T cells, travel around the body to detect possible threats by eliminating the proteins that they do not recognise as safe proteins—referred to as non-self proteins. Intrusion Detection Agents (IDAs) roam the network to detect suspicious behaviours in a manner that mimics the behaviour of T cells. The Intrusion Response System (IRS) also borrows mechanisms from the stigmergic paradigm of a colony of ants. At the time of foraging, the ants use the environment to diffuse a chemical substance called the pheromone which traces the route for the other ants from the nest to the source of food. Intrusion Response Agents (IRAs) roam the network to respond to the IDAs’ alerts, mimicking the behaviour of the ants to trace the route to the alert and give the response. The two natural systems exhibit a social behaviour by the organisation of their entities, T cells and ants, which is not possible without the functionality of mobility.KeywordsIntrusion DetectionAgent MobilityIntrusion Detection SystemComputer SecurityHuman Immune SystemThese keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Read moreA framework for adaptive, cost-sensitive intrusion detection and response system
Intrusion detection has been at the center of intense research in the last decade owing to the rapid increase of sophisticated attacks on computer systems. Typically, intrusion detection refers to a variety of techniques for detecting attacks in the form of malicious and unauthorized activities. There are three broad categories of detection approaches: (a) misuse-based technique that relies on pre-specified attack signatures, (b) anomaly-based approach, that typically depends on normal patterns classifying any deviation from normal as malicious; and (c) specification-based technique that although operates in a similar fashion to anomaly-based approach, employs a model of valid program behavior in a form of specifications requiring user expertise. When intrusive behavior is detected, it is desirable to take (evasive and/or corrective) actions to thwart attacks and ensure safety of the computing environment. Such countermeasures are referred to as intrusion response. Although the intrusion response component is often integrated with the Intrusion Detection System (IDS), it receives considerably less attention than IDS research owing to the inherent complexity in developing and deploying response in an automated fashion. As such, traditionally, triggering an intrusion response is left as part of the administrators responsibility, requiring a high-degree of expertise. In this work we present an integrated approach to intrusion detection and response based on the technique for monitoring abnormal patterns in the program behavior. The proposed model effectively combines the advantages of anomaly-based and specification-based approaches recognizing a known behavior through the specifications of normal and abnormal patterns and classifying unknown patterns using a machine-learning algorithm. Such combination not only allows adaptation of the specification-based detection to the new patterns, but also provides a method for automatic development of specifications. In addition to detection, our framework incorporates preemptive response. By preemption, we imply deploying response before a monitored pattern is classified completely as an intrusion. Such response deployment is likely to stop an intrusion before it can affect the system. However, preemption also inherently suffers from false positives; i.e., responses are deployed to deter correct execution which may look intrusive in its initial phase. To reduce false positives, we have developed a multi-phase response selection and deployment mechanism based on the evaluation of the cost information of the system damage caused by potential intrusion and candidate responses.
Read moreNetwork security intrusion detection system based on incremental improved convolutional neural network model
With the popularization and development of network knowledge, network intruders are increasing, and the attack mode has been updated. Intrusion detection technology is a kind of active defense technology, which can extract the key information from the network system, and quickly judge and protect the internal or external network intrusion. Intrusion detection is a kind of active security technology, which provides real-time protection for internal attacks, external attacks and misuse, and it plays an important role in ensuring network security. However, with the diversification of intrusion technology, the traditional intrusion detection system cannot meet the requirements of the current network security. Therefore, the implementation of intrusion detection needs diversifying. In this context, we apply neural network technology to the network intrusion detection system to solve the problem. In this paper, on the basis of intrusion detection method, we analyze the development history and the present situation of intrusion detection technology, and summarize the intrusion detection system overview and architecture. The neural network intrusion detection is divided into data acquisition, data analysis, pretreatment, intrusion behavior detection and testing.
Read moreEfficient Working of Signature Based Intrusion Detection Technique in Computer Networks
The subject of Computer Network Intrusion Detection System (IDS) is a very interesting research topic actively pursued by many investigators. The goal of intrusion detection is to monitor network assets and to detect anomalous behaviour and misuse. This concept has been around for the past several years but only recently, it has seen a dramatic rise in interest of researchers and system developers for incorporation into the overall information security infrastructure. In today's world, the concept of information has been moved to the digital size from conventional size. Protection of the data stored in the digital archive and is easily accessibility at any time have become a quite important phenomenon. In this concept, intrusion detection and prevention systems as security tools are widely used today [1]. In this paper, a signature based intrusion detection system approach has been proposed for computer network security. This paper is based on the efficient working of the Signature based intrusion detection method and protects the computer network against the intrusion or the unspecified packets.
Read moreAttack-aware Security Function Management
Attack-aware Security Function Management
Automated Intrusion Detection and Prevention System over SPIT (AIDPoS)
Systems employing the Internet and Voice over Internet Protocol (VoIP) are alternative to the legacy landline telephony system. The services offered by these systems allow users to communicate with their family members, friends, banks and business partners whenever they are online. Particularly, the VoIP service is popular with the Internet users because charges are bound into usually fixed access costs making the price of the long distance calls themselves appear economical and even free. However, VoIP services have several disadvantages. One of the disadvantages of VoIP is, it is exposed to Internet security vulnerabilities, threats and attacks. The attacks come in many forms. One of the methods to attack the VoIP service, is by sending a Spam over Internet Telephony (SPIT). SPIT is normally executed by malicious parties initiating automated, unsolicited, and unwanted communications that used VoIP or video conferencing services, just like an email SPAM. Solutions to mitigate SPIT are still lacking. To defense a VoIP system from SPIT, we have come out with the idea of Automated Intrusion Detection and Prevention System over SPIT (AIDPoS) that can detect and prevent SPIT from external parties to enter the VoIP network. AIDPoS is a combination system of Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) on Voice over IP (VoIP) server. This is an experimental research to find a solution to combat SPIT if it happens in the future. Our result shows that an automated Intrusion detection and Prevention system over SPIT attack is feasible. Our work is on an open source VoIP network. Other vulnerabilities and threats are important, but beyond our research scope and is not covered in this paper.
Read more