Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Autonomous Rule Creation for Intrusion Detection

Conference ·

Many computational intelligence techniques for anomaly based network intrusion detection can be found in literature. Translating a newly discovered intrusion recognition criteria into a distributable rule can be a human intensive effort. This paper explores a multi-modal genetic algorithm solution for autonomous rule creation. This algorithm focuses on the process of creating rules once an intrusion has been identified, rather than the evolution of rules to provide a solution for intrusion detection. The algorithm was demonstrated on anomalous ICMP network packets (input) and Snort rules (output of the algorithm). Output rules were sorted according to a fitness value and any duplicates were removed. The experimental results on ten test cases demonstrated a 100 percent rule alert rate. Out of 33,804 test packets 3 produced false positives. Each test case produced a minimum of three rule variations that could be used as candidates for a production system.

Research Organization:
Idaho National Laboratory (INL)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC07-05ID14517
OSTI ID:
1023508
Report Number(s):
INL/CON-10-20413
Country of Publication:
United States
Language:
English

Similar Records

Computationally Efficient Neural Network Intrusion Security Awareness
Conference · Sat Aug 01 00:00:00 EDT 2009 · OSTI ID:968573

Applying Fast String Matching to Intrusion Detection
Conference · Sun Dec 31 23:00:00 EST 2000 · OSTI ID:975767

Security Evaluation of Two Intrusion Detection Systems in Smart Grid SCADA Environment
Conference · Sat Sep 01 00:00:00 EDT 2018 · 2018 North American Power Symposium (NAPS) · OSTI ID:1985687