Remove Plagiarism Deliver within 12 hours

profileltdprinwival
PSmarkup_TOBEPARAPHRASEDWITHOUTCHANGINGTHEREALMEANING..docx.pdf

Filename: TO BE PARAPHRASED WITHOUT CHANGING THE REAL MEANING..docx Date: 2019-03-03 14:38 UTC

Results of plagiarism analysis from 2019-03-03 14:41 UTC

197 matches from 23 sources, of which 23 are online sources.

PlagLevel: 50.7%

[0] (34 matches, 45.5%) from dtstc.ugr.es/~jedv/descargas/2009_CoSe09...n-Techniques,-systems-and-challenges.pdf [1] (32 matches, 41.0%) from https://www.researchgate.net/publication...trusion_Detection_and_Prevention_Systems [2] (27 matches, 30.8%) from https://www.sciencedirect.com/science/article/pii/S0167404808000692 [3] (20 matches, 29.1%) from https://paperap.com/paper-on-anomaly-based-intrusion-detection-system/ [4] (14 matches, 18.6%) from https://www.ijert.org/research/multivari...s-attack-detection-IJERTCONV3IS12011.pdf [5] (11 matches, 11.1%) from https://www.ijais.org/research/volume10/number2/lata-2015-ijais-451471.pdf [6] (9 matches, 11.0%) from https://www.slideshare.net/HiteshMohapatra/anomaly-detection-82811108 [7] (7 matches, 8.3%) from www.rroij.com/open-access/a-network-intr...ring-and-outlier-detection.php?aid=44668 [8] (8 matches, 6.3%) from www.ijettjournal.org/volume-4/issue-9/IJETT-V4I9P125.pdf [9] (4 matches, 6.3%) from https://www.researchgate.net/publication...rails_for_Host-Based_Intrusion_Detection [10] (4 matches, 5.2%) from https://docplayer.net/679915-Novel-trend...denial-of-service-attacks-detection.html [11] (4 matches, 3.3%) from https://www.ijser.org/researchpaper/A-Sy...ey-on-Network-Attacks-Classification.pdf

(+ 1 documents with identical matches) [13] (4 matches, 3.2%) from https://pdfs.semanticscholar.org/ce15/39d19ca2192e7af578ef7208fd8f97a6ee2f.pdf [14] (3 matches, 3.0%) from https://www.coursehero.com/file/p68b2bt5...ointed-out-First-this-kind-of-A-NIDS-is/ [15] (2 matches, 2.9%) from https://www.researchgate.net/profile/Xia...etection-via-Intelligent-Fuzzy-Logic.pdf [16] (2 matches, 1.2%) from https://www.sciencedirect.com/topics/computer-science/recognize-activity [17] (2 matches, 1.4%) from https://www.researchgate.net/profile/Dzu...f-literature-review-Face-Recognition.pdf [18] (2 matches, 1.2%) from https://www.sciencedirect.com/science/article/pii/S138912860700062X [19] (1 matches, 0.9%) from https://patents.google.com/patent/US9185095B1/en [20] (1 matches, 0.7%) from www.academia.edu/6385552/Anomaly_detection_based_on_K-means_and_EM_in_network [21] (1 matches, 0.3%) from https://www.coursehero.com/file/p7vt93c/...-IDS-is-constructed-manually-by-a-human/ [22] (1 matches, 0.5%) from https://www.sciencedirect.com/science/article/pii/S0926580511001294

Settings Sensitivity: Medium Bibliography: Consider text Citation detection: Reduce PlagLevel Whitelist: --

Analyzed document

=====================1/4====================== Statistical techniques In Statistics based IDS, the behavior of the system is represented from a random viewpoint and the network traffic activity is captured and a profile representing its stochastic behavior is created.[3] [0] [10] [15] ... This profile is based on metrics such as the traffic rate, the number of packets for each protocol, the rate of connections, the number of different IP addresses, etc.[0] [3] [4] [10] ... Two datasets of network traffic are considered during the anomaly detection process:[0] [3] [7] [1] ... one corresponds to the currently observed profile over time, and the other is for the previously trained statistical profile.[0] [2] [4] [3] ... As the network events occur, the current profile is determined and an anomaly score estimated by comparison of the two behaviors.[4] [3] [1] [0] ... The score normally indicates the degree of irregularity for a specific event, such that the intrusion detection system will flag the occurrence of an anomaly when the score surpasses a certain threshold.[0] [3] [1] [4] ... The earliest statistical approaches, both network oriented and host oriented IDS, corresponded to univariate models, which modelled the parameters as independent Gaussian random variables, thus defining an acceptable range of values for every variable.[0] [2] [9] [6] ... Later, multivariate models that consider the correlations between two or more metrics were proposed.[0] [1] [3] [9] ... These are useful because experimental data have shown that a better level of discrimination can be obtained from combinations of related measures rather than individually.[0] [1] [2] [3] ... Other studies have considered time series models, which use an interval timer, together with an event counter or resource measure, and take into account the order and the inter-arrival times of the observations as well as their values.[0] [1] [2] [3] ... Thus, an observed traffic instance will be labelled as abnormal if its probability of occurrence is too low at a given time.[0] [3] [1] [13] ... Apart from their inherent features for use as anomaly based techniques, statistical A-NIDS

approaches have a number of virtues.[0] [1] [2] [3] ... Firstly, they do not require prior knowledge about the normal activity of the target system;[0] [1] [2] [3] ... instead, they have the ability to learn the expected behavior of the system from observations.[1] [3] [0] [2] ... Secondly, statistical methods can provide accurate notification of malicious activities occurring over long periods of time.[0] [2] [1] [3] ... However, some drawbacks should also be pointed out.[0] [1] [2] [3] ... First, this kind of A-NIDS is susceptible to be trained by an attacker in such a way that the network traffic generated during the attack is considered as normal.[0] [3] [1] [14] ... Second, setting the values of the different parameters/metrics is a difficult task, especially because the balance between false positives and false negatives is affected.[0] [2] [3] [1] ... Moreover, a statistical distribution per =====================2/4====================== variable is assumed, but not all behaviors can be modelled by using stochastic methods.[1] [2] [0] [3] ... Furthermore, most of these schemes rely on the assumption of a quasi-stationary process, which is not always realistic.[0] [1] [7] [2] ... 2.3.2.3 Knowledge based techniques Knowledge based IDS techniques try to capture the claimed behavior from available system data (protocol specifications, network traffic instances, etc.[7] [0] [5] [3] ...). The so-called expert system approach is one of the most widely used knowledge-based IDS schemes.[0] [4] [1] [8] ... However, like other A-NIDS methodologies, expert systems can also be classified into other, different categories .[0] [2] [1] Expert systems are intended to classify the audit data according to a set of rules, involving three steps.[1] [2] [4] [0] ... First, different attributes and classes are identified from the training data.[0] [2] [4] [5] ... Second, a set of classification rules, parameters or procedures are deduced.[0] [2] [4] [5] ... Third, the audit data are classified accordingly.[0] [2] [4] [5] ... More restrictive/particular in some senses are specification based anomaly methods, for which the desired model is manually constructed by a human expert, in terms of a set of rules (the specifications) that seek to determine legitimate system behavior.[4] [0] [1] [10] ... If the specifications are complete enough, the model will be able to detect illegitimate behavioral patterns.[4] [10] [2] [1] ... Moreover, the number of false positives is reduced, mainly because this kind of system avoids the problem of harmless activities, not previously observed, being reported as intrusions.[0] [1] [4] [2] ... The most significant advantages of current approaches to anomaly detection are those of robustness and flexibility.[0] [2] [1] Their main drawback is that the development of high-quality knowledge is often difficult and time-consuming.[0] [5] [1] This problem, however, is common to other A-NIDS Markov Chain Model A Markov model is a stochastic model used to model sequential or temporal randomly changing systems.[0] [1] It enables computation and reasoning with the model that are not easily solved or managed and gives a method to model the dependencies of the current information with previous information[93]. It is composed of emission of output, states and transition scheme between states. Patterns recognition, learning statistics of sequential data and performing estimation and prediction are the goals that Markov model accomplishes[94]. Hidden Markov model (HMM) is a stochastic model and a Markov technique where the states of the model are hidden with each state emitting observable output.[16] It is a statistical model where the system being modelled is assumed to be a =====================3/4====================== Markov process with unknown parameters. It allows variant structures to be modelled directly, allows more sequences to be significantly found, helps in generating alignments that corresponds each machine to one column in the alignment, and it ensures that models are readable. The problem with Markov model is to determine the hidden parameters from the observable parameters and difficulty in solving and managing models.[18] [17] Unlike a regular Markov model, where the state transition probabilities are the only parameters and the state of the system is directly observable, in a hidden Markov model, the only visible elements are the variables of the system that are influenced by the state of the system, and the state of the system itself is hidden[[11] [18] 95]. Computing Markov model memory and time algorithm is relatively expensive, in every sequence there are many HMMs thus difficult to choose and lacks one-to-one correspondence between symbols and states.

Feature selection Feature selection (FS) is a process of chucking out the irrelevant and redundant features from the total feature space during the Pre-Processing step[152]. Moreover it reduces the negative effect on the actual machine learning algorithms[153]. Feature subset selection methodologies are broadly categorized into, the filter method and the wrapper method. The selection of feature subset in filter method is entirely dependent on the characteristics of the dataset not on the induction algorithm.[22] Moreover, there are two directional approaches followed by filter method are forward selection and backward selection in sequential order[154]. In Sequential Forward Selection, we initiate with an empty set and insert rest of the features one by one. In Sequential backward selection, we initiate with full set of features and remove them one

by one[155]. However wrapper method is entirely dependent on the induction algorithm, i.e. a predestined classifier is implemented to assess the selected set of features. The Feature Selection is a renowned dimensionality reduction techniques for a given feature space. In dimensionality reduction mechanism a subset of the most pertinent features that contributes in machine learning process are chosen and other inappropriate and repetitive features are deleted[156]. A single irrelevant feature in the dataset tends to confuses ML process. Before the learning phase all the irrelevant features are removed in pre-processing phase, to reduce the =====================4/4====================== adverse impact of these unrelated features on the classification algorithms[157]. The Feature reduction techniques have been readily identified in the areas of ML and data mining for years. 3.5.2.1 Best First This search strategy searches the subsets from feature space by using greedy hill climbing ampli- fied with backtracking. The intensity of backtracking may be controlled by locating an amount of successive non-improving nodes[162]. This search method works both in SFS and SBE mode or may start from any random point and search bidirectional. Therefore it have various control panels like direction, Search termination, start set and lookup Cache Size etc. 3.5.2.2 Greedy-step wise Performs search of subset from the feature space in forward as well as in backward direction using greedy hill climbing without backtracking facility[163]. It can also generate record of ranked features by scanning the feature space from one end to other end making the record of the order in which the features were selected. 3.5.2.3 Scatter search VI It uses sequential scatter search algorithm for finding out the subsets in feature space. It starts with some significant and diverse subsets and stops depending on some threshold value or when no improvement is revealed[164]. Some of the control panels it have are combinations, seed and threshold.