Fuzzy logic based intrusion detection system as a service for malicious port scanning traffic detection

Firas Saidi, Zouheir Trabelsi, Henda Ben Ghazela

Research output: Chapter in Book/Report/Conference proceedingConference contribution

2 Citations (Scopus)

Abstract

Port scanning is a cyber-network attack allows cyber terrorists to gather valuable information about target hosts namely defense, governmental and banks servers by trying to identify instantly open ports, which correspond to specific services on the cloud, such as HTTP, DNS, and email. The basic role of Intrusion Detection Systems (IDSs) is to monitor networks and systems for malicious activities, policy violations attacks and unauthorized information gathering activities. In this paper, we proposed a TCP port scanning detection framework, based on fuzzy logic controller, which uses fuzzy rules base and the Mamdani inference method. The proposed platform is a Fuzzy IDS as a Service, which enables network administrators and cyber security specialists to follow in real time the network traffic behavior, i.e., the Port Scanning Criticity Level (PSCL). A SaaS dynamic dashboard is implemented to quickly and efficiently identify malicious port scanning activities. Experimentations and evaluations showed the efficiency of the proposed system in multilevel port scanning detection compared to Snort and the related IDS systems.

Original languageEnglish
Title of host publication16th ACS/IEEE International Conference on Computer Systems and Applications, AICCSA 2019
PublisherIEEE Computer Society
ISBN (Electronic)9781728150529
DOIs
Publication statusPublished - Nov 2019
Event16th ACS/IEEE International Conference on Computer Systems and Applications, AICCSA 2019 - Abu Dhabi, United Arab Emirates
Duration: Nov 3 2019Nov 7 2019

Publication series

NameProceedings of IEEE/ACS International Conference on Computer Systems and Applications, AICCSA
Volume2019-November
ISSN (Print)2161-5322
ISSN (Electronic)2161-5330

Conference

Conference16th ACS/IEEE International Conference on Computer Systems and Applications, AICCSA 2019
Country/TerritoryUnited Arab Emirates
CityAbu Dhabi
Period11/3/1911/7/19

Keywords

  • Fuzzy IDS as a Service
  • Fuzzy logic controller
  • IDS
  • Mamdani inference
  • PSCL
  • Port Scanning

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Hardware and Architecture
  • Signal Processing
  • Control and Systems Engineering
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Fuzzy logic based intrusion detection system as a service for malicious port scanning traffic detection'. Together they form a unique fingerprint.

Cite this