Bootstrap based T2 chart with hybrid James Stein and SDCM for network anomaly detection

Muhammad Ahsan*, Muhammad Mashuri, Hidayaml Kliusna, Wibawati

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The conventional multivariate chart based on Shewhart approach will face a problem when it is utilized in monitoring the multiple outliers. To overcome the situation, the James-Stein estimator and Successive Difference Covariance Matrix can be adopted to improve the estimated mean vector and covariance matrix, respectively. Attacks in the network have a similar nature as the multiple outliers. Therefore, by improving its estimated mean vector and covariance matrix, the multivariate Hotelling's T chart can be exploited for detecting network attacks as an intnision detection system. In this paper, the performance of the Hotelling's T2 is updated using the James-Stein estimator and Successive Difference Covariance Matrix estimators in monitoring network anomalies. The bootstrap resampling method is applied in estimating the control limit of the proposed IDS. Further, the reputable NSL-KDD dataset is used as a standard in assessing the proposed chart performance. The proposed IDS demonstrates a good performance for the training dataset with hit rate detection of 0.9175. Meanwhile, for the testing dataset. the proposed method excels the other charts with hit rate detection of 0.8557.

Original languageEnglish
Title of host publicationInternational Conference on Mathematics, Computational Sciences and Statistics 2020
EditorsCicik Alfiniyah, Fatmawati, Windarto
PublisherAmerican Institute of Physics Inc.
ISBN (Electronic)9780735440739
DOIs
Publication statusPublished - 26 Feb 2021
Externally publishedYes
EventInternational Conference on Mathematics, Computational Sciences and Statistics 2020, ICoMCoS 2020 - Surabaya, Indonesia
Duration: 29 Sept 2020 → …

Publication series

NameAIP Conference Proceedings
Volume2329
ISSN (Print)0094-243X
ISSN (Electronic)1551-7616

Conference

ConferenceInternational Conference on Mathematics, Computational Sciences and Statistics 2020, ICoMCoS 2020
Country/TerritoryIndonesia
CitySurabaya
Period29/09/20 → …

Fingerprint

Dive into the research topics of 'Bootstrap based T2 chart with hybrid James Stein and SDCM for network anomaly detection'. Together they form a unique fingerprint.

Cite this