Fuzzy logic based anomaly detection for embedded network security cyber sensor

Ondrej Linda, Milos Manic, Todd Vollmer, Jason Wright

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

57 Scopus citations

Abstract

Resiliency and security in critical infrastructure control systems in the modern world of cyber terrorism constitute a relevant concern. Developing a network security system specifically tailored to the requirements of such critical assets is of a primary importance. This paper proposes a novel learning algorithm for anomaly based network security cyber sensor together with its hardware implementation. The presented learning algorithm constructs a fuzzy logic rule base modeling the normal network behavior. Individual fuzzy rules are extracted directly from the stream of incoming packets using an online clustering algorithm. This learning algorithm was specifically developed to comply with the constrained computational requirements of low-cost embedded network security cyber sensors. The performance of the system was evaluated on a set of network data recorded from an experimental test-bed mimicking the environment of a critical infrastructure control system.

Original languageEnglish
Title of host publicationIEEE SSCI 2011
Subtitle of host publicationSymposium Series on Computational Intelligence - CICS 2011: 2011 IEEE Symposium on Computational Intelligence in Cyber Security
Pages202-209
Number of pages8
DOIs
StatePublished - 2011
Externally publishedYes
EventSymposium Series on Computational Intelligence, IEEE SSCI2011 - 2011 IEEE Symposium on Computational Intelligence in Cyber Security, CICS 2011 - Paris, France
Duration: Apr 11 2011Apr 15 2011

Publication series

NameIEEE SSCI 2011: Symposium Series on Computational Intelligence - CICS 2011: 2011 IEEE Symposium on Computational Intelligence in Cyber Security

Conference

ConferenceSymposium Series on Computational Intelligence, IEEE SSCI2011 - 2011 IEEE Symposium on Computational Intelligence in Cyber Security, CICS 2011
Country/TerritoryFrance
CityParis
Period04/11/1104/15/11

Keywords

  • Anomaly Detection
  • Cyber Sensor
  • Embedded Systems
  • Fuzzy Logic System
  • Online Clustering

Fingerprint

Dive into the research topics of 'Fuzzy logic based anomaly detection for embedded network security cyber sensor'. Together they form a unique fingerprint.

Cite this