Title
En-ABC: An ensemble artificial bee colony based anomaly detection scheme for cloud environment.
Abstract
With an exponential increase in the usage of different types of services and applications in cloud computing environment, the identification of malicious behavior of different nodes becomes challenging due to the diversity of traffic patterns generated from various services and applications. Most of the existing solutions reported in the literature are restricted with respect to the usage of a specific technique applicable to single class datasets. But in real life scenarios, applications and services especially in cloud environment may have multi-class datasets. Moreover, non-linear behavior among the dataset attributes generates additional challenges for identification of nodes behavior, and it has not been exploited to its full potential in the existing solutions. This can lead to performance bottlenecks with respect to the identification of malicious behavior of different nodes. Motivated from these facts, this paper proposes an Ensemble Artificial Bee Colony based Anomaly Detection Scheme (En-ABC) for multi-class datasets in cloud environment. En-ABC has following components for identification of malicious behavior of nodes-(i) feature selection and optimization, (ii) data clustering, and (iii) identification of anomalous behavior of nodes. The feature selection and optimization model in En-ABC has been built using Restricted Boltzmann Machine and Unscented Kalman Filter (to handle the non-linear behavior of dataset attributes) respectively. Moreover, Artificial Bee Colony-based Fuzzy C-means clustering technique is used to obtain an optimal clustering based on two objective functions, i.e., Mean Square Deviation and Dunn Index (to handle the participation of attributes in multiple clustered datasets). Then, a profile of normal/abnormal behavior has been built using clustering results for detection of the anomalies. Finally, the performance of the proposed scheme has been compared with the existing schemes (CM, SVM, ML-IDS and MSADA) using various parameters such as-detection, false alarm, and accuracy rates. Experimental results on benchmark (NSL-KDD, NAB and IBRL) and synthetic datasets validate the effectiveness of the proposed scheme.
Year
DOI
Venue
2020
10.1016/j.jpdc.2019.09.013
Journal of Parallel and Distributed Computing
Keywords
Field
DocType
Anomaly detection,Artificial bee colony algorithm,Cloud computing,Fuzzy C-means clustering,Restricted Boltzmann machine,Unscented Kalman filter
Data mining,Anomaly detection,Restricted Boltzmann machine,False alarm,Feature selection,Computer science,Support vector machine,Dunn index,Cluster analysis,Distributed computing,Cloud computing
Journal
Volume
ISSN
Citations 
135
0743-7315
5
PageRank 
References 
Authors
0.40
0
8
Name
Order
Citations
PageRank
Sahil Garg126740.16
Kuljeet Kaur219519.59
Shalini Batra38513.53
Gagangeet Singh Aujla422624.02
Graham Morgan515019.15
Neeraj Kumar62889236.13
albert y zomaya742743.75
Rajiv Ranjan84747267.72