مجله علمی  رایانش نرم و فناوری اطلاعات

مجله علمی رایانش نرم و فناوری اطلاعات

ارائه یک روش هوشمند جهت تشخیص نفوذ در محیط رایانش ابری با بهینه‌سازی شبکه عصبی توسط الگوریتم ژنتیک

نوع مقاله : مقاله پژوهشی فارسی

نویسندگان
1 گروه مهندسی برق و کامپیوتر، واحد مهاباد، دانشگاه آزاد اسلامی، مهاباد، ایران.
2 گروه مهندسی برق و کامپیوتر، واحد خلخال، دانشگاه آزاد اسلامی، خلخال، ایران.
چکیده
با توجه به گسترش فزایندۀ استفاده از محیط‌های محاسباتی ابری در سالیان اخیر، چالش‌های متعددی نیز فرا‌‌روی کاربران این محیط‌ها قرار گرفته است. یکی از مهمترین چالش‌های کنونی جهت استفاده عملیاتی از محیط رایانش ابری، مسئله امنیت در این نوع محاسبات است و یکی از مسائل چالش برانگیز در امنیت رایانش ابری نیز مسئلۀ تشخیص نفوذ در این محیط است که اگر به‌ درستی به انجام نرسد و دقت کافی در این سیستم‌ها وجود نداشته باشد می‌تواند موجب خطرات فراوانی مانند: افشای اطلاعات و سوء استفاده‌های دیگر گردد. بنابراین تشخیص نفوذ و دقت سیستم‌های کمکی تعبیه شده جهت این موضوع بسیار حیاتی و مهم است. تاکنون روش‌های زیادی برای بهینه کردن این چالش توسط محققینی که در این حوزه فعالیت می‌کنند پیشنهاد شده است؛ اکثر روش‌های پیشنهاد شده دارای دقت تشخیص نفوذ نسبتاً پایینی می‌باشند که یکی از دلایل آن، عدم تقارن بین ویژگی‌های اطلاعاتی نامربوط و اضافی مجموعه داده‌ها است. در این مقاله، یک روش جدید برای تشخیص نفوذ در بستر ابر با استفاده از دسته-بندی شبکۀ عصبی بهبود یافته مبتنی بر الگوریتم ژنتیک جهت بهبود و افزایش دقت تشخیص، ارائه شده است. برای این منظور، ابتدا برای کاهش ابعاد مجموعه داده از الگوریتم تحلیل مولفه اصلی (PCA) استفاده شده و سپس، با استفاده از دسته‌بندی شبکه عصبی مصنوعی ترافیک نرمال و تهاجمی از هم تشخیص داده می‌شوند. در ادامه پارامتر‌های شبکه‌عصبی مصنوعی با استفاد از الگوریتم ژنتیک مورد بهینه‌سازی قرار می‌گیرند. در پایان، کارایی روش پیشنهادی بر روی مجموعه داده NSL-KDD به عنوان یک مجموعه داده استاندارد و جامع برای ارزیابی سیستم‌های تشخیص نفوذ در محیط متلب مورد آزمایش و ارزیابی قرار می‌گیرد و با نتایج سه روش مطرح دیگر مقایسه می‌شود. نتایج مقایسه نشان می‌دهد که روش پیشنهادی با دقت تشخیص 99.41% در مقایسه با روش‌های دیگر دارای قابلیت بهتری بوده و می‌تواند حملات را با دقت بالاتری تشخیص دهد.
کلیدواژه‌ها

[1] H. Abusaimeh, "Distributed denial of service attacks in cloud computing," Int. J. Adv. Comput. Sci. Appl., vol. 11, no. 6, pp. 163–168, 2020, doi: 10.14569/IJACSA.2020.0110621.
[2] I. T. Aziz, I. H. Abdulqadder, and T. A. Jawad, "Distributed denial of service attacks on cloud computing environment," Cihan Univ.-Erbil Sci. J., vol. 6, no. 1, pp. 47–52, 2022, doi: 10.24086/cuesj.v6n1y2022.pp47-52.
[3] G. S. Kushwah and V. Ranga, "Voting extreme learning machine based distributed denial of service attack detection in cloud computing," J. Inf. Secur. Appl., vol. 53, Art. no. 102532, 2020, doi: 10.1016/j.jisa.2020.102532.
[4] A. Singh and B. B. Gupta, "Distributed denial-of-service (DDoS) attacks and defense mechanisms in various web-enabled computing platforms: Issues, challenges, and future research directions," Int. J. Semantic Web Inf. Syst., vol. 18, no. 1, pp. 1–43, 2022, doi: 10.4018/IJSWIS.297143.
[5] A. D. Lopez, A. P. Mohan, and S. Nair, "Network traffic behavioral analytics for detection of DDoS attacks," SMU Data Sci. Rev., vol. 2, no. 1, Art. no. 14, 2019.
[6] M. Mazini, B. Shirazi, and I. Mahdavi, "Anomaly network-based intrusion detection system using a reliable hybrid artificial bee colony and AdaBoost algorithms," J. King Saud Univ.-Comput. Inf. Sci., vol. 31, no. 4, pp. 541–553, 2019, doi: 10.1016/j.jksuci.2018.03.011.
[7] P. D. Bojović, I. Bašičević, S. Ocovaj, and M. Popović, "A practical approach to detection of distributed denial-of-service attacks using a hybrid detection method," Comput. Electr. Eng., vol. 73, pp. 84–96, 2019, doi: 10.1016/j.compeleceng.2018.11.017.
[8] J. Kim, J. Kim, H. Kim, M. Shim, and E. Choi, "CNN-based network intrusion detection against denial-of-service attacks," Electronics, vol. 9, no. 6, Art. no. 916, 2020, doi: 10.3390/electronics9060916.
[9] L. Lv, W. Wang, Z. Zhang, and X. Liu, "A novel intrusion detection system based on an optimal hybrid kernel extreme learning machine," Knowl.-Based Syst., vol. 195, Art. no. 105648, 2020, doi: 10.1016/j.knosys.2020.105648.
[10] S. Sambangi and L. Gondi, "A machine learning approach for DDoS (distributed denial of service) attack detection using multiple linear regression," Proceedings, vol. 63, no. 1, Art. no. 51, 2020, doi: 10.3390/proceedings2020063051.
[11] P. Ghosh, D. Sarkar, J. Sharma, and S. Phadikar, "An intrusion detection system using modified-firefly algorithm in cloud environment," Int. J. Digit. Crime Forensics, vol. 13, no. 2, pp. 77–93, 2021, doi: 10.4018/IJDCF.2021030105.
[12] G. S. Kushwah and V. Ranga, "DDoS attacks detection in cloud computing using ANN and imperialistic competitive algorithm," in Proc. Int. Conf. Artif. Intell. Sustain. Comput. (ICSISCET), Singapore: Springer, 2022, pp. 253–263, doi: 10.1007/978-981-19-1653-3_20.
[13] S. Mani, B. Sundan, A. Thangasamy, and L. Govindaraj, "A new intrusion detection and prevention system using a hybrid deep neural network in cloud environment," in Proc. Int. Conf. Comput. Netw., Big Data IoT (ICCBI), Singapore: Springer, 2022, pp. 981–994, doi: 10.1007/978-981-19-0898-9_77.
[14] S. Krishnaveni, S. Sivamohan, S. S. Sridhar, and S. Prabakaran, "Efficient feature selection and classification through ensemble method for network intrusion detection on cloud computing," Cluster Comput., vol. 24, no. 3, pp. 1761–1779, 2021, doi: 10.1007/s10586-020-03222-7.
[15] G. S. Kushwah and V. Ranga, "Optimized extreme learning machine for detecting DDoS attacks in cloud computing," Comput. Secur., vol. 105, Art. no. 102260, 2021, doi: 10.1016/j.cose.2021.102260.
[16] E. Moharamkhani, M. Y. F. Hendi, E. Bandar, A. Izadkhasti, and R. S. Raza, "Intrusion detection system based firefly algorithm-random forest for cloud computing," Concurrency Comput. Pract. Exp., vol. 34, no. 24, Art. no. e7220, 2022, doi: 10.1002/cpe.7220.
[17] S. Sokkalingam and R. Ramakrishnan, "An intelligent intrusion detection system for distributed denial of service attacks: A support vector machine with hybrid optimization algorithm based approach," Concurrency Comput. Pract. Exp., vol. 34, no. 27, Art. no. e7334, 2022, doi: 10.1002/cpe.7334.
[18] S. Sureshkumar, G. P. Venkatesan, and R. Santhosh, "Detection of DDoS attacks on cloud computing environment using altered convolutional deep belief networks," Int. J. Comput. Netw. Inf. Secur., vol. 15, no. 5, pp. 63–72, 2023, doi: 10.5815/ijcnis.2023.05.06.
[19] A. Thangasamy, B. Sundan, and L. Govindaraj, "A novel framework for DDoS attacks detection using hybrid LSTM techniques," Comput. Syst. Sci. Eng., vol. 45, no. 3, pp. 2553–2567, 2023, doi: 10.32604/csse.2023.032078.
[20] T. Kurita, "Principal component analysis (PCA)," in Computer Vision: A Reference Guide, Cham, Switzerland: Springer, 2021, pp. 1013–1016, doi: 10.1007/978-3-030-63416-2_346.
[21] M. Greenacre, P. J. Groenen, T. Hastie, A. I. d’Enza, A. Markos, and E. Tuzhilina, "Principal component analysis," Nat. Rev. Methods Primers, vol. 2, no. 1, Art. no. 100, 2022, doi: 10.1038/s43586-022-00184-w.
[22] B. Alhijawi and A. Awajan, "Genetic algorithms: Theory, genetic operators, solutions, and applications," Evol. Intell., vol. 17, no. 3, pp. 1245–1256, 2024, doi: 10.1007/s12065-023-00822-5.
[23] M. S. Pervez and D. M. Farid, "Feature selection and intrusion classification in NSL-KDD cup 99 dataset employing SVMs," in Proc. 8th Int. Conf. Softw., Knowl., Inf. Manag. Appl. (SKIMA), Dhaka, Bangladesh, 2014, pp. 1–6, doi: 10.1109/SKIMA.2014.7083560.