IDPS Signature Classification with a Reject Option and the Incorporation of Expert Knowledge

07/19/2022
by   Hidetoshi Kawaguchi, et al.
0

As the importance of intrusion detection and prevention systems (IDPSs) increases, great costs are incurred to manage the signatures that are generated by malicious communication pattern files. Experts in network security need to classify signatures by importance for an IDPS to work. We propose and evaluate a machine learning signature classification model with a reject option (RO) to reduce the cost of setting up an IDPS. To train the proposed model, it is essential to design features that are effective for signature classification. Experts classify signatures with predefined if-then rules. An if-then rule returns a label of low, medium, high, or unknown importance based on keyword matching of the elements in the signature. Therefore, we first design two types of features, symbolic features (SFs) and keyword features (KFs), which are used in keyword matching for the if-then rules. Next, we design web information and message features (WMFs) to capture the properties of signatures that do not match the if-then rules. The WMFs are extracted as term frequency-inverse document frequency (TF-IDF) features of the message text in the signatures. The features are obtained by web scraping from the referenced external attack identification systems described in the signature. Because failure needs to be minimized in the classification of IDPS signatures, as in the medical field, we consider introducing a RO in our proposed model. The effectiveness of the proposed classification model is evaluated in experiments with two real datasets composed of signatures labeled by experts: a dataset that can be classified with if-then rules and a dataset with elements that do not match an if-then rule. In the experiment, the proposed model is evaluated. In both cases, the combined SFs and WMFs performed better than the combined SFs and KFs. In addition, we also performed feature analysis.

READ FULL TEXT

page 1

page 4

research
05/28/2018

Identification of Flaws in the Design of Signatures for Intrusion Detection Systems

Signature-based Intrusion Detection System (SIDS) provides a promising s...
research
03/30/2010

Offline Signature Identification by Fusion of Multiple Classifiers using Statistical Learning Theory

This paper uses Support Vector Machines (SVM) to fuse multiple classifie...
research
02/02/2010

Fusion of Multiple Matchers using SVM for Offline Signature Identification

This paper uses Support Vector Machines (SVM) to fuse multiple classifie...
research
07/18/2018

Bag-of-Visual-Words for Signature-Based Multi-Script Document Retrieval

An end-to-end architecture for multi-script document retrieval using han...
research
02/20/2022

Redactable Signature with Compactness from Set-Commitment

Redactable signature allows anyone to remove parts of a signed message w...
research
03/28/2019

Extending Signature-based Intrusion Detection Systems WithBayesian Abductive Reasoning

Evolving cybersecurity threats are a persistent challenge for systemadmi...
research
10/13/2021

Identification of Metallic Objects using Spectral Magnetic Polarizability Tensor Signatures: Object Classification

The early detection of terrorist threat objects, such as guns and knives...

Please sign up or login with your details

Forgot password? Click here to reset