Application of genetic-based AI methods for enhancing network intrusion detection systems.

Authors

  • Shujaat Ali Rathore Department of Computer Science & Information Technology, University of Kotli, Azad Jammu and Kashmir. Author
  • Muhammad Hammad u Salam Department of Computer Science & Information Technology, University of Kotli, Azad Jammu and Kashmir Author
  • Nazir Ahmad Department of Computer Science, National College of Business Administration & Economics, Lahore, Sub-Campus Multan, 60000, Pakistan Author

DOI:

https://doi.org/10.63075/sghp1c92

Keywords:

 Artificial Intelligence (AI); Current Active Directory List (CADL); Decision Tree Algorithm; Genetic Approaches; Network Intrusion Detection Systems (NIDS); Protocol Standardisation; Mutation and Crossover; Wireshark Tool; Network Security; Machine Learning; Anomaly Detection.

Abstract

The detection and evaluation of potential threats within communication networks is a vital role performed by network intrusion detection systems (NIDS). The information obtained from these systems, such as the frequency and nature of attacks, provides significant support to other protective measures like firewalls. A typical NIDS employs sensors that examine all inbound and outbound traffic, identify suspicious packets, and then forward those packets along with an alert message to a central server for storage and correlation with additional events. In this study, the protocol structure was first standardised. Next, a genetic technique was implemented to create mutation and crossover values for device recognition. Following this, a modified J48 decision tree algorithm was applied to perform the search process. The proposed approach achieves superior performance compared to existing methods. As an initial stage in intrusion recognition, a 64-byte structured protocol standardisation method was introduced. The Wireshark tool was utilised to capture the communication activity of the network, covering all possible interactions. The gathered packets were arranged into an array containing details such as frame information, protocol type, hardware identifiers, source and destination IP addresses, MAC addresses, and data. These elements were then processed through the 64-byte structured protocol standardisation. Since all required attributes are extracted in a unified manner, identification of MAC and IP addresses from packets is achieved more efficiently. In the subsequent stage, product and device characteristics were derived from the least and most significant 16 bits of the MAC address. Using crossover and mutation functions, the genetic method compared unknown devices against the Current Active Directory List (CADL).

Downloads

Download data is not yet available.

Downloads

Published

2024-12-22

How to Cite

Application of genetic-based AI methods for enhancing network intrusion detection systems. (2024). Annual Methodological Archive Research Review, 2(6), 1-15. https://doi.org/10.63075/sghp1c92

Similar Articles

111-120 of 1763

You may also start an advanced similarity search for this article.