Optimization of BPN Parameters Using PSO for Intrusion Detection in Cloud Environment

preprint OA: closed
Full text JSON View at publisher

Abstract

Abstract The usage of internet is getting increased in all aspect, like from building various models that are fully connect with internet to the usage of digital media for 24/7. As this is rising in a way, on the other side the concern about “data security” is raising and everybody’s information needs to be protected from any other attacks or can say there shouldn’t be no data leakage. So, for detecting these attacks, intrusion detection system is placed. But placing this traditional Intrusion Detection System (IDS) will increase the concerns of security even more, so to amp the process integration of latest technology such deep learning comes in action. Thereby this paper proposes an IDS using Back-propagation Network (BPN) where intrusions are identified based on the system calls that we collected in the dataset KDD cup 99. Also, to increase the optimization of neural network, we used Particle Swarm Optimization (PSO) thereby increase the accurate detection of the system saying if that is normal or abnormal in behavior. We evaluate our proposed model with other methods like ANFIS, F-GNP, FCM in which the proposed model gives 96.5% accurate detection.
Full text 99,438 characters · extracted from preprint-html · click to expand
Optimization of BPN Parameters Using PSO for Intrusion Detection in Cloud Environment | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Optimization of BPN Parameters Using PSO for Intrusion Detection in Cloud Environment Sajith P J, G Nagarajan This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-1298053/v1 This work is licensed under a CC BY 4.0 License Status: Published Journal Publication published 21 Jun, 2023 Read the published version in Soft Computing → Version 1 posted 4 You are reading this latest preprint version Abstract The usage of internet is getting increased in all aspect, like from building various models that are fully connect with internet to the usage of digital media for 24/7. As this is rising in a way, on the other side the concern about “data security” is raising and everybody’s information needs to be protected from any other attacks or can say there shouldn’t be no data leakage. So, for detecting these attacks, intrusion detection system is placed. But placing this traditional Intrusion Detection System (IDS) will increase the concerns of security even more, so to amp the process integration of latest technology such deep learning comes in action. Thereby this paper proposes an IDS using Back-propagation Network (BPN) where intrusions are identified based on the system calls that we collected in the dataset KDD cup 99. Also, to increase the optimization of neural network, we used Particle Swarm Optimization (PSO) thereby increase the accurate detection of the system saying if that is normal or abnormal in behavior. We evaluate our proposed model with other methods like ANFIS, F-GNP, FCM in which the proposed model gives 96.5% accurate detection. Back Propagation Network Intrusion Detection System Neural Network Particle Swarm Optimization System Calls Figures Figure 1 Figure 2 Figure 3 Figure 4 Figure 5 Figure 6 Figure 7 Figure 8 Figure 9 Figure 10 Figure 11 Figure 12 Figure 13 Figure 14 Figure 15 Figure 16 Figure 17 1. Introduction The issue of ensuring data has existed since data has been overseen. Be that as it may, as innovation advances and data the board frameworks become increasingly incredible, the issue of authorizing data security additionally turns out to be more basic [ 1 ]. The development of this electronic climate accompanies a comparing development of electronic wrongdoing where the system is utilized either as a device to carry out the wrongdoing or as an objective of the wrongdoing [ 1 ].Many networks did not consider insurance to guarantee against network attacks. That is why many networks have been hacked in recent times. The inability to achieve their framework puts many organizations and associations at serious risk of misfortune. Generally, a solitary assault can cost a large number of dollars in expected income. Also, that is only the start. The harms of assaults incorporate not just loss of licensed innovation and risk for bargained client information (the time/cash spent to recuperate from the assault) yet in addition client certainty and market advantage. The security of systems and organizations needs to be improved to protect the infrastructure from hazards [ 2 – 5 ]. Joining the escalation of electronic errors, the Secure Data Foundation's plan, for example, is gradually becoming a test of the Interruption Recognition Framework (IDS) for preventing and identifying events.. Figure 1 delineates the interruption identification framework and outer/inward organization interruption assaults. Outfitted for recognizing awful interruptions is the prescient model (for eg: a classifier), to assemble it is the interruption identifier learning task what's more, typical associations. As of late, extensive research has been done to apply neural organizations to identify barriers. An ANN contains a collection of components which are deeply interconnected. Provide a collection of information sources and the desired yield, and the transition from donation to yield is governed by the interrelated loads in the component preparation. By adjusting these interrelationships, the organization can match the appropriate revenue. In IDS the ability of the high capacity to carry learning for visual demonstration makes neural organizations adaptable and stunning. Although, the time taken to run the model from a big dataset is very large. The aggressive behavior of the IDS can be accurately expected for this. There are two kinds of interruption discovery frameworks are accessible. Host based Intrusion Detection System (HIDS) which utilizes data accumulated from a solitary host, for example, review trail, log records, framework call groupings and so forth NIDS utilizes the assembled information by breaking down the system organization traffic. HIDS regularly screens and investigations the single host occasions, for the most part the host-based models utilize rule-based example coordinating with approaches [ 9 ][ 10 ]. For every client a profile is made and the HIDS persistently screens and thinks about the current review record and the current client profiles. On the off chance that there is deviation over specific limit esteem then the current movement is considered as a vindictive action. The expanded utilization of the systems and system related assets, brought about expanded number of gadgets and clients associated with the organizations. A Network based Intrusion Detection System (NIDS) screens and examines the organization traffic to shield a framework from network-based malignant exercises. NIDS works at chosen framework on an organization and which examinations network traffic, bundle by parcel to recognize interruption. On the off chance that NIDS is introduced in the organization, it diminishes the responsibility of interruption identification on each individual framework (Figure 2 ). 1.1 Key Highlights This paper focus over building a Intrusion detection system which is been integrated with DL could potentially analyze behavior of attacks in which following are some key notes; a. Intrusion detection system using BPN b. With collection of system calls that is been passed over this network for analyzing the behavior c. For improving the optimization power of neural networks, PSO is been utilized d. The proposed system is compared with other models like ANFIS, F-GNP, and FCM in which the proposed model outperformed with accuracy 96.5%. Organization of paper: As we already come across the overview and the types of IDS in Section 1, rest is as follows; Section 2 depict related works based on IDS integrated with DL then followed by Section 3 with methodology, Section 4 with Implementation and Result, and at last section 5 with conclusion. 2. Related Works In [ 11 ] the creator proposed an information mining structure for building interruption identification models. The main thought is to process the programs of information mining specifically, grouping, meta-learning, affiliation manages, and continuous scenes to review information for figuring abuse and irregularity location models that precisely catch the behavior (i.e., designs) of interruptions and ordinary exercises. In spite of the fact that, proposed discovery structure can identify a greater level of new and old U2R and PROBING assaults, it missed countless new DOS and R2L assaults. In [ 12 ], it is generally centered around information mining procedures that are being utilized for the purposes of such, and afterward introduced a groundbreaking thought on how information mining can help IDSs by using bi-clustering as an apparatus to investigate the traffic of network and upgrade IDS’s. An investigation of scholastic exploration utilized the accepted standard benchmark information, to improvise the efficiency of interruption identification rate of KDDCup 99. In third International Knowledge Discovery and Data Mining Tools competition, KDDcup 99 was used. The information was generated in such a way as to handle the 1998 DARPA Interruption Location (ID) Assessment Organization's tcpdump information. The challenge was, to make a prescient structure, to arrange the organization associations into 2 classes: Attack or Normal. Assaults are ordered into the ('DoS') Denial of Service, ('U2R') User-to-Root, 'Test', ('R2L') Remote-to-Local, classes. The digging review information for the models of mechanized for (MADAMID) ID was utilized as highlight development structure in KDDCup 99 rivalry [ 13 ]. MADAMID yields 41 highlights: initial 9 highlights are fundamental highlights of a bundle, content highlights are 10-22, highlights of traffic are 23-31, and based highlights are 32-41 has. Decisions of the accessible dataset are: full dataset and 10% corresponding information. The nitty gritty assessment after effects of KDDCup 98 and KDDCup 99 test was distributed in [ 14 ]. The Third International Knowledge Discovery and Data Mining Tools Competition task continued as the basic work. Machine learning solutions could be found from it. Most of the published works used only 10% of the training and testing data. Very few custom built dataset was used. With the dataset [ 17 ] of KDDcup 99 a recent survey was conducted on the id of machine learning based. Most of the results published on KDDcup 99 have been utilized for dimensionality reduction in featured engineering methods [ 16 ]. Most of the newly available machine learning used the same dataset. Few studies have used the custom-built dataset. The outputs are partially comparable to the KDDcup99 contest. In [ 18 ], by the use of Naive Bayesian network explored the Bayesian networks for ID, in which leaf node = features and root node = class connection. Later, [ 20 ] to ID, the application of the Naive Bayes network is identified and by means of detailed experimental analysis, challenge of KDDCup 99 the winning entries with which compared, in ’Probe’ and ’U2R’ categories better performance is given by a Bayesian network. In [ 21 ], on parison-window estimators based method of non-parametric density estimation was studied by the use of Normal distribution and Gaussian kernels. Model temporal and spatial data were used to identify complex anomalies. NIDS proposed a genetic algorithm for this[ 22 ]. Using System Particle Optimization, Agent Colony Optimization and Colony Clustering [ 19 ] for ID, a set of intelligence techniques and techniques of synchronization learning overview is provided. 3. Methodology Figure 3 depict the overall workflow of proposed model in which the system call is collected from the KDD cup 99 dataset are given for the pre-processing stage. Here all the system calls are collected in raw fashion, by using the sliding window mechanism these are pre-processed and are passed for feature selection in which for better optimization we use Particle Swarm Optimization and then passed over to the decision network were using the selected features, neural network (BPN) will process these features into several layer and give the result as system behaves properly or not. 3.1 Dataset Description For this model for execution, we utilized KDD cup 99 dataset created in MIT Lincoln Laboratories. The Dataset is made by presenting physically produced network-based assaults. Different attacks that can be potentially found in an organization is characterized in a brief form concerning KDD interruption discovery evaluation dataset[ 6 ]. System will be analyzed at different levels such as system accuracy, system ability and cost to differentiate abnormal behavior and normal behavior. IDS can work based on either privileged process behavior or user behavior. The privileged processes have the privileges to access and use system resources. All the normal system calls are gathered in the normal trace step. In abnormal trace step, abnormal system call sequences are gathered. Data set of KDD cup 99 is utilized for collecting abnormal and normal traces. The stide, xlock, ps and login processes sequences of system calls are collected from KDD cup 99 data set. The repeated execution of these processes generates system call sequences which are recorded in separate files. Each trace system call sequence contains ten to thousand system calls. These traces are collected while there are no malicious activities. The examples of abnormal processes are iprcp, buffer overflow, sun sendmailcp etc. Another example is Syslog attack. It uses the interfaces like syslog which makes buffer overflow in send mail. Intrusion traces contains three sunsendmailcp attacks, forwarding loops five error conditions, two traces of syslog-local attacks, the syslog-remote attacks of two traces, and an attacks of decode two traces. Each trace contains two attributes: process ID and a system call value. The process ID is used to identify the specific system call. An abnormal process will not have the sequences of normal system calls (Figure 4 ). The current sequence of system calls can be compared with the sequence of normal system calls stored and deviations can be detected[ 7 ][ 8 ]. 3.2 Data Pre-processing After collecting the system call sequences of from the active process, the next step is preprocessing of data. The gathered information about system call is basic raw collection data. The techniques used for preprocessing have to be applied on raw data to make the data set into processing dataset. A unique number will be assigned to each and every system call name. For instance, 8 for open, 9 for close, 74 for mmap etc. The unique numbering will make it is easy to access the system call, reduces data complexity and convenient format for processing. With proper sliding window mechanism, long system call sequence numbers can be processed. The normal behavioral data base uses the window size of 3. For example, the normal behavior database can be created from the following system call sequence Open, read, mmap, mmap, open, read, close for the given sequence, the system calls will be put in position 1, position 2 and position 3 as shown in below table. The window size decides the pairs generated. Table 1 depict the sequence of system call in proposed system. Table 1 System call sequence Current Position1 Position2 Position3 Open 1 Read 1 mmap 1 mmap 1 Read 1 mmap 1 mmap 1 mmap 1 mmap 1 Read 1 mmap 1 mmap 1 Open 1 mmap 1 mmap 1 Open 1 mmap 1 Open 1 mmap 1 mmap 1 Open 1 Read 1 mmap 1 Open 1 Read 1 mmap 1 Open 1 Read 1 Close 1 Open 1 Read 1 Close 1 Read 1 Close 1 By analyzing the data set it is found that certain system calls are executed frequently. These systems call executions may be followed by different system calls. For example, the read is followed by different system calls and executed two times. Therefore, all system calls are recorded first and then, expanded the database for different sequences. The expanded format is given in the following Table 2 . Table 2 Expanded system call Current Position1 Position2 Position3 Open 1 Read 1 mmap 1 , close 1 mmap 1 Read 1 mmap 1 , close 1 Mmap 1 Open 1 mmap 1 mmap 1 , open 1 Open 1 , read 1 Close 1 , read 1 Using the sliding window, many system call sequences are produced and stored in database. After data base is preprocessed from raw information, normal behavior rule can be easily formed from this data set. 3.3 Particle Swarm Optimization Here once it is normalized, these are now passed over to feature selection process where you naturally or physically select those highlights which contribute most to your expectation variable or yield in which you are keen on. So, for that PSO is used here for feature extraction. PSO is an equal estimation, which has the advantages of straightforward execution, high exactness and quick assembly[ 19 ]. To track down the best arrangement, PSO instates some irregular arrangements in arrangement space, these arrangements are a few particles, where characterize the molecule speed v i and the molecule position x i . In the meantime, use the capacity of health to determine if the circumstances of the particles are ideal, use pbest and gbest to capture the individual best circumstances and social opportunity independently. For every particle, note its well-being, it will also be pbest if it is better contrasted with pbest , and it will be like gbest expect better contrasted with gbest , update the speed and location of the molecule. The speed of molecules and position update rules are according to the accompaniment; $${v}_{i}=w{v}_{i}+{c}_{1}\times rand\left(\right)\times \left({ pbest }_{i}-{x}_{i}\right)+{c}_{2}\times rand\left(\right)\times ({ gbest }_{i}-{x}_{i}) {x}_{i}={x}_{i}+{v}_{i}$$ 1 where v i is the speed of the molecule, w is inactivity weight, rand() is an irregular worth somewhere in the range of 0 and c 1 and c 2 is the current situation of the molecule c 1 and c 2 are speed increase factor. If the velocity or circumstance of the particles exceeds the degree of stroke, it will be defined as the most limiting velocity or the circumstance of the cutoff. At the point where the molecule has been reinvigorated, it will keep reheating until the best game plan is found. Regularly finding the best position or appearing at the most remarkable number of cycles will halt the demand. In BPN, the number of concealed core layer points affects the generation of the independent learning stage and the fine-tuning of coordinated learning stage. Along these lines, the quantity of covered up layer hubs in the profound adapting should be enhanced by PSO calculation to improve the exhibition of the organization. 3.4 Back Propagation Network Learn an example for back propagation network. When you provide examples of networking algorithm and it changes the weight of the network, for a particular input the required output will given when completed the training. For simple pattern identification and mapping tasks Back Propagation Networks can be used. As mentioned now, you need to give a particular input in order to get the desired output. It is mentioned in Figure 5 . If it is the first pattern to the network, we would like the output to be 0 1 as shown in Figure 6. (yellow line =1 and black= 0 like previous examples). Training Pair means the input and its corresponding target. Once the network is trained, it will provide the desired output for any of the input patterns. If the network is trained once then it will yield the required output to any input. Now let's see how it goes. All weights must first initialize the network by giving small random numbers (between -1 and 1). Now you need to perform the forward pass (give the input and calculate the output). The calculations will give you a different output than you need (the target), all weights will be random. Then each neuron’s error is calculated. Here, Actual Output = Target (i.e. what you actually get - what you want). The error get from the output is then used for changing the weight. Then we can reduce the error part. By this way each neuron’s output will get nearer to required output value. It is known as reverse pass. This step is iterated until the error is minimal. Algorithm1: BPN 1. Give the information and take the yield from the organization. Since the main weight is irregular numbers, hence recollect that the principal yield can be anything. 2. Presently we need to address the blunder of neuron B. Blunder is the thing that you need – What you really get, all in all: ErrorB = OutputB (1-OutputB) (TargetB – OutputB) The "Yield (1-Output)" term is fundamental in the condition due to the Sigmoid Function – in the event that we were just utilizing a limit neuron it would simply be (Target - Output). 3. Presently you need to alter the weight. Let WAB = introductory weight and W+AB = trained (new) weight. W+AB = WAB + (ErrorB x OutputA). Notice that it is the yield of the interfacing (neuron A) we use (not B). This is the way we update every one of the heaps on the yield layer. 4. Figure the Errors for the secret layer neurons We can't ascertain it straightforwardly from the yield layer since we don't have an objective. That is the reason this calculation is known by that name). This is finished by taking mistakes from the need yield neurons and by means of the heap, running them back to get errors of covered up layer. For model assuming neuron An is associated as to B and C as appeared, for creating a blunder for A we need take the blunders from B and C. ErrorA = Output A (1 - Output A) (ErrorC WAC + ErrorB WAB) Again, the factor "Yield (1 - Output)" is available due to the sigmoid crushing capacity. 5. Assuming you get the mistake for the hidden layer neurons once, the subsequent stage to change the secret layer weight. Consequently we can rehash this strategy and make it workable for quite a few layered networks. Once in a while there might be questions about its capacity. It shows the estimation of a FCN. It comprises, number of data sources =2, covered up layer neurons = 3 and yield = 2. Where w + = new and recalculated weight, w (without addendum) =old weight. The opposite interaction can be determined similarly. 4. Implementation And Results Initially this model is implemented over wamp server and are run in python environment over the i5 Core intel system. The proposed model is evaluated under two performance measure such as Detection Rate (DR) and False Alarm Rate (FAR), also it is compared with other models such as ANFIS, F-GNP and FCM. a. Detection Rate : Detection rate indicates, among all attack data, the percentage of detected attack, and is provided as, DR: TP/ (TP + TN) *100 b. False Alarm Rate : False Alarm Rate is otherwise known as false positive(FP). It is the proportion that normal data is falsely detected as attack behavior. Accuracy is classified as: true positive(TP) and true negative(TN).It is the proportion of correctly classified data. Table 3 Performance Measure Models FAR DR (%) ANFIS 3.4 92 F-GNP 1.9 80 FCM 2.4 85 BPN 4.4 96.5% Table 3 shows the comparison of various systems like ANFIS, F-GNP and FCM with our system under the performance measure DR and FAR. The FAR of our system is 4.4 while it is 1.9 for F-GNP. While taking DR our system shows a detection rate of 96.5% which is better than all the other compared models. ANFIS: The ANFIS structure maps contributions through input enrollment works and related boundaries, and afterward through yield participations and related boundaries to yields. During the learning interaction, the boundaries related with enrollment capacities changes. An incline vector empowers the figuring of these limits, giving an extent of how well the FIS models the data/yield data for a given game plan of limits. In the wake of procuring the tendency vector, any of the couple of smoothing out timetables could be applied to change the limits for reducing some mix-up measure. This learning method works correspondingly as that of neural associations. When appeared differently in relation to the generally FIS, ANFIS is really astounding. This makes the fuzzy system to acquire from the data they model (Figure 7 ). F-GNP: GNP has been supportive of acted like one of the transformative calculations[ 17 ]. It was utilized to programmed program age for efficient specialist practices. GNP is addressed by chart structures which comprise of three kind hubs, i.e., start hub, judgment hub and preparing hub. These hubs are associated with one another as coordinated diagram structures which give more benefits, i.e., reusability of hubs and flexibility to mostly discernible Markov choice issues. GNP has been effectively applied to the issues in unique conditions, for example, lift administrative control frameworks, stock exchanging markets and tile world (Figure 8 ). FCM: Corresponding to every data point via assigning membership value to every cluster this algorithm works. On the distance between the data point and the cluster center it depends. Towards the particular cluster center gives the more is its membership when more the data is closer to cluster center. i.e, each data point’s sum of membership = 1. According to formula, cluster centers are updated after performing each iteration membership. It is shown in Figure 9 . Figure 10 and 11 depict the detection rate and FAR of the proposed system while comparing it with other methods. Figure 12 a, b shows the starting snapshot of the proposed system in which we have several modules and each module contain its corresponding operation. Figure 13 a, b depicts the initializing the starting module and once the KDD dataset is loaded then a pop displaying data loaded successfully. Figure 14 depict the pre-processing stage of KDD. Figure 15 shows the PSO process after pre-processing stage. Figure 16 shows the BPN training process where the inputs are given before optimizing it and are entirely process to gain the final report. And once the training done, then a pop will be displayed. Figure 17 depict the overall view of BPN outperforming than other existing system in a graphical representation. 5. Conclusion From this, it is clear that in today’s world, how everyone gives much priority to the “security” and for that so much efficient models been released every day in much different forms. So, like that here we build an effective IDS using BPN in which system calls are collected from KDD cup 99 and are pre-processed using the sliding window and finally gave to neural network for better analysis and finally predict that, if the system behaves in normal or abnormal fashion. Also, we compared our system with other existing models under detection rate and FAR in which our system performs better with 96.5%. In future many other advance optimization techniques can be used for boosting the neural network, also other neural networks can be brought up by various researchers who can dig dive by getting inspired by this paper. Abbreviations DL Deep Learning BPN Back Propagation Network IDS Intrusion Detection System NIDS Network Intrusion Detection System HIDS Host based Intrusion Detection System DR Detection Rate FAR False Alarm Rate U2L User to Local R2L Root to Local DoS Denial of Service PSO Particle Swarm Optimization NN Neural Network ANFIS Adaptive Neuro Fuzzy Inference System F-GNP Fuzzy Graph Neural Process FCM Fuzzy C Mean Clustering Declarations Funding: The authors did not receive financial support from any organization for the submitted work. Conflicts of interest/Competing interests: The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper. Availability of data and material: ‘Not applicable’, Authors’ contributions: ‘Not applicable’ Code availability: ‘Not applicable’, Consent to participate: ‘Not applicable’ Ethics approval: Compliance with Ethical Standards. Consent for publication: Authors give consent to Soft Computing Journal to publish their article. References Elmasry W, Akbulut A, Abdul Halim Zaim (2021) A Design of an Integrated Cloud-based Intrusion Detection System with Third Party Cloud Service. Open Computer Science 11(1):365–379 Salvatore Pontarelli G, Bianchi S, Teofili Traffic-aware Design of a High Speed FPGA Network Intrusion Detection System.Digital Object Identifier10.1109/TC.2012.105, IEEE TRANSACTIONS ON COMPUTERS. Elrawy MF, Awad AI, Hesham FAH (2018) Intrusion detection systems for IoT-based smart environments: a survey. Journal of Cloud Computing 7(1):1–20 Thilagam T, Aruna R (2021) "Intrusion detection for network based cloud computing by custom RC-NN and optimization."ICT Express Idhammad M, Afdel K, Mustapha Belouch (2018) Distributed intrusion detection system for cloud environments based on data mining techniques. Procedia Computer Science 127:35–41 Deshpande P, Sharma SC, Peddoju SK, Junaid S (2018) HIDS: A host based intrusion detection system for cloud computing environment. International Journal of System Assurance Engineering and Management 9(3):567–576 Apurva S, Patil, Dipak R Patil“ Offline host based intrusion detection based on analysis of system calls”, International Journal for Research in Engineering Application & Management (IJREAM) ISSN: 2494- 9150, Vol-02, Issue 04, July 2016 Ramprakash P, Sakthivadivel M, Krishnaraj N, Ramprasath J “Host-based intrusion detection system using sequence of system calls”, International Journal of Engineering and Management Research, Volume-4, Issue-2, April-2014, ISSN No.: 2250-0758 Sekhar R, Sasirekha K, Raja PS, Thangavel K (2021) A novel GPU based intrusion detection system using deep autoencoder with Fruitfly optimization. SN Applied Sciences 3(6):1–16 Wei P, Li Y, Zhang Z, Hu T, Li Z, Liu D (2019) An optimization method for intrusion detection classification model based on deep belief network. IEEE Access 7:87593–87605 Vinayakumar R, Alazab M, Soman KP, Poornachandran P (2019) Ameer Al-Nemrat, and Sitalakshmi Venkatraman. "Deep learning approach for intelligent intrusion detection system. IEEE Access 7:41525–41550 Kim J, Kim J, Kim H, Shim M, Choi E (2020) "CNN-based network intrusion detection against denial-of-service attacks." Electronics 9, no. 6 : 916 Amudha P, Karthik S, Sivakumari S (2015) "A hybrid swarm intelligence algorithm for intrusion detection using significant features." The Scientific World Journal (2015) Staudemeyer RC (2015) Applying long short-term memory recurrent neural networks to intrusion detection. South African Computer Journal 56(1):136–154 Huang X (2021) "Network Intrusion Detection Based on an Improved Long-Short-Term Memory Model in Combination with Multiple Spatiotemporal Structures." Wireless Communications and Mobile Computing (2021) Tan X, Su S, Zuo Z, Guo X, Sun X (2019) "Intrusion detection of UAVs based on the deep belief network optimized by PSO." Sensors 19, no. 24 : 5529 Azad C (2017) "Fuzzy min–max neural network and particle swarm optimization based intrusion detection system. Microsyst Technol 23(4):907–918 Venkatraman S, Alazab M (2018) "Use of data visualisation for zero-day malware detection." Security and Communication Networks (2018) Kunhare N, Tiwari R, Dhar J (2020) "Particle swarm optimization and feature selection for intrusion detection system." Sādhanā 45, no. 1 : 1-14 Liu J, Yang D, Lian M, Li M (2021) Research on Intrusion Detection Based on Particle Swarm Optimization in IoT. IEEE Access 9:38254–38268 Solanki M, Dhamdhere V (2015) ”Intrusion detection system using means of data mining by using c 4.5 algorithm”,International Journal of Application or Innovation in Engineering & Management, Volume 4, Issue 5, Yin C, Zhu Y, Fei J, He X (2017) A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks. IEEE Access 5:21954–21961 Cite Share Download PDF Status: Published Journal Publication published 21 Jun, 2023 Read the published version in Soft Computing → Version 1 posted Reviews received at journal 01 Feb, 2022 Reviewers invited by journal 01 Feb, 2022 Editor assigned by journal 31 Jan, 2022 First submitted to journal 25 Jan, 2022 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-1298053","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":80632833,"identity":"8bb0bffe-4ee6-4d03-bcc1-fd816654b188","order_by":0,"name":"Sajith P J","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA1UlEQVRIie2PMQqDQBBFR1KH7cKEQLzCBEEN5DDrBYKQJqUXCLaGHCGNIFhvZ6OkNdgkWAcsLSziegB3y0D2NTPFf8wfAIPhJxEASMCZ3HmorxBfR1Ih/VPESUxTI+tZxbvzw+HoPO5B9yKw2UrMK/uodHAsdnLrT4Zjsd31xhWNRAlSCfK6SqXCqVEqRdtLJUuqrNdUhDtdSdkl17sy/uL6SE6Q1Mvc54TqXzws2gaHbRDHVfbszwebbVTFUMAC5YZTEufjk8IisDq5MaFOGwwGw3/yBRQsSI8FcH9fAAAAAElFTkSuQmCC","orcid":"https://orcid.org/0000-0001-7514-7662","institution":"Sathyabama Institute of Science and Technology","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Sajith","middleName":"P","lastName":"J","suffix":""},{"id":80632834,"identity":"d0692fef-3db2-4add-a9e5-237b33123fe9","order_by":1,"name":"G Nagarajan","email":"","orcid":"","institution":"Sathyabama Institute of Science and Technology","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"G","middleName":"","lastName":"Nagarajan","suffix":""}],"badges":[],"createdAt":"2022-01-26 07:05:05","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-1298053/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-1298053/v1","draftVersion":[],"editorialEvents":[{"content":"https://doi.org/10.1007/s00500-023-08737-1","type":"published","date":"2023-06-21T21:16:56+00:00"}],"editorialNote":"","failedWorkflow":false,"files":[{"id":17918369,"identity":"07498fe0-fa84-4e47-aa75-77b755558036","added_by":"auto","created_at":"2022-02-03 20:45:36","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":43991,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eIDS using DL basic flow\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig1.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/20b28c96eaf2f953ddd00c0f.png"},{"id":17918807,"identity":"9d8a6497-26b5-49c7-b170-86c2c6503401","added_by":"auto","created_at":"2022-02-03 20:51:36","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":15058,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eTypes of IDS in simple network system\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig2.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/7cb2a8be1e2b829a3e820406.png"},{"id":17918810,"identity":"09d58225-99b2-45da-842d-0811a9a6aea7","added_by":"auto","created_at":"2022-02-03 20:51:36","extension":"png","order_by":3,"title":"Figure 3","display":"","copyAsset":false,"role":"figure","size":42111,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eBlock diagram of proposed IDS using BPN\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig3.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/cb3398f16bab5b96d5a98463.png"},{"id":17918363,"identity":"22a6559d-57fd-4890-b9b6-d279314fe9b0","added_by":"auto","created_at":"2022-02-03 20:45:36","extension":"png","order_by":4,"title":"Figure 4","display":"","copyAsset":false,"role":"figure","size":56764,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eSample system call sequence\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig4.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/dbe512fc65e9bd95615d38bb.png"},{"id":17918364,"identity":"1622dd8c-d3e8-4870-b21a-e4e442850fca","added_by":"auto","created_at":"2022-02-03 20:45:36","extension":"png","order_by":5,"title":"Figure 5","display":"","copyAsset":false,"role":"figure","size":52074,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eBPN\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig5.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/62934f2ed7c90c604cb87661.png"},{"id":17918374,"identity":"40991199-3b84-41e2-9afc-926f5a98dac4","added_by":"auto","created_at":"2022-02-03 20:45:36","extension":"png","order_by":6,"title":"Figure 6","display":"","copyAsset":false,"role":"figure","size":158204,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eTraining of BPN\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig6.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/b8992f153f34fe6754c12769.png"},{"id":17918587,"identity":"f85b4a18-2872-48ab-b06d-34b1b979ed85","added_by":"auto","created_at":"2022-02-03 20:48:36","extension":"png","order_by":7,"title":"Figure 7","display":"","copyAsset":false,"role":"figure","size":127230,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eANFIS design\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig7.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/dfe84ecc05ac5c4ba52dc82f.png"},{"id":17918375,"identity":"1993497b-8896-4f39-aa91-28e276010990","added_by":"auto","created_at":"2022-02-03 20:45:36","extension":"png","order_by":8,"title":"Figure 8","display":"","copyAsset":false,"role":"figure","size":63374,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eF-GNP architecture\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig8.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/c52e48db09f1d8cf1e01c0dc.png"},{"id":17919480,"identity":"a5b630a1-abe9-4255-9623-ee9606300995","added_by":"auto","created_at":"2022-02-03 20:57:36","extension":"png","order_by":9,"title":"Figure 9","display":"","copyAsset":false,"role":"figure","size":23991,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eFCM design\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig9.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/ee748bf9a0d7925af3a5719f.png"},{"id":17919205,"identity":"46e7792e-f66b-408b-bd7c-34a0cd23d0f2","added_by":"auto","created_at":"2022-02-03 20:54:36","extension":"png","order_by":10,"title":"Figure 10","display":"","copyAsset":false,"role":"figure","size":105192,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eComparative analysis of various models under DR\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig10.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/f6eb3068eeeabb723e822ccd.png"},{"id":17919203,"identity":"e987c5d8-6493-47e3-8c06-30144851f03f","added_by":"auto","created_at":"2022-02-03 20:54:36","extension":"png","order_by":11,"title":"Figure 11","display":"","copyAsset":false,"role":"figure","size":121952,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eComparative analysis of various models under FAR\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig11.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/974a4f0df422b3bec55e92c8.png"},{"id":17918590,"identity":"41679dfa-e4e8-4871-8a7b-013de6a8ec28","added_by":"auto","created_at":"2022-02-03 20:48:36","extension":"png","order_by":12,"title":"Figure 12","display":"","copyAsset":false,"role":"figure","size":685929,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003ea. starting process of the model, b) the process of the model\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig12.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/0d94d227f3568e19015ab422.png"},{"id":17919206,"identity":"68b75f22-6aa8-48a8-ac3b-a759e4080b2b","added_by":"auto","created_at":"2022-02-03 20:54:36","extension":"png","order_by":13,"title":"Figure 13","display":"","copyAsset":false,"role":"figure","size":71549,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003ea. Initializing the first process, b) once the dataset is loaded, pop up will displayed\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig13.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/df2f3ce6930dd1b8234f8667.png"},{"id":17918812,"identity":"e1f08ac7-a893-42b4-bc00-32a8cb3a9419","added_by":"auto","created_at":"2022-02-03 20:51:36","extension":"png","order_by":14,"title":"Figure 14","display":"","copyAsset":false,"role":"figure","size":425294,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003ePre-processing snapshot of KDD dataset\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig14.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/c5dccd98be2401a9401069bf.png"},{"id":17918594,"identity":"0b5003e5-121c-415c-beff-e21af22a0535","added_by":"auto","created_at":"2022-02-03 20:48:36","extension":"png","order_by":15,"title":"Figure 15","display":"","copyAsset":false,"role":"figure","size":158183,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003ePSO process after the pre-processing stage\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig15.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/fd2f36dc1688fe45b2e947fe.png"},{"id":17918595,"identity":"c0b8e322-4bef-47f5-a0ea-31d399070f47","added_by":"auto","created_at":"2022-02-03 20:48:36","extension":"png","order_by":16,"title":"Figure 16","display":"","copyAsset":false,"role":"figure","size":237531,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eSnapshot showing BPN process after optimization is done\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"fig16.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/3e70138753ad30cb1d1ba432.png"},{"id":17918378,"identity":"8f268aba-4d78-41f9-8e1a-0f5648920a06","added_by":"auto","created_at":"2022-02-03 20:45:37","extension":"png","order_by":17,"title":"Figure 17","display":"","copyAsset":false,"role":"figure","size":118130,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eComparison of existing and proposed system in overall fashion\u003c/strong\u003e\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e","description":"","filename":"fig17.png","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/e1b380d1d5fb670c4c799e81.png"},{"id":44731405,"identity":"9163048e-8efa-4854-8e0f-acba1e1f63d4","added_by":"auto","created_at":"2023-10-16 21:43:16","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":2756097,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-1298053/v1/a1c9d63d-50b0-4dd2-8d86-bf294b580c58.pdf"}],"financialInterests":"","formattedTitle":"\u003cp\u003eOptimization of BPN Parameters Using PSO for Intrusion Detection in Cloud Environment\u003c/p\u003e","fulltext":[{"header":"1. Introduction","content":"\u003cp\u003eThe issue of ensuring data has existed since data has been overseen. Be that as it may, as innovation advances and data the board frameworks become increasingly incredible, the issue of authorizing data security additionally turns out to be more basic [\u003cspan class=\"CitationRef\"\u003e1\u003c/span\u003e]. The development of this electronic climate accompanies a comparing development of electronic wrongdoing where the system is utilized either as a device to carry out the wrongdoing or as an objective of the wrongdoing [\u003cspan class=\"CitationRef\"\u003e1\u003c/span\u003e].Many networks did not consider insurance to guarantee against network attacks. That is why many networks have been hacked in recent times. The inability to achieve their framework puts many organizations and associations at serious risk of misfortune. Generally, a solitary assault can cost a large number of dollars in expected income. Also, that is only the start. The harms of assaults incorporate not just loss of licensed innovation and risk for bargained client information (the time/cash spent to recuperate from the assault) yet in addition client certainty and market advantage. The security of systems and organizations needs to be improved to protect the infrastructure from hazards [\u003cspan class=\"CitationRef\"\u003e2\u003c/span\u003e\u0026ndash;\u003cspan class=\"CitationRef\"\u003e5\u003c/span\u003e]. Joining the escalation of electronic errors, the Secure Data Foundation\u0026apos;s plan, for example, is gradually becoming a test of the Interruption Recognition Framework (IDS) for preventing and identifying events.. Figure \u003cspan class=\"InternalRef\"\u003e1\u003c/span\u003e delineates the interruption identification framework and outer/inward organization interruption assaults. Outfitted for recognizing awful interruptions is the prescient model (for eg: a classifier), to assemble it is the interruption identifier learning task what\u0026apos;s more, typical associations. As of late, extensive research has been done to apply neural organizations to identify barriers. An ANN contains a collection of components which are deeply interconnected. Provide a collection of information sources and the desired yield, and the transition from donation to yield is governed by the interrelated loads in the component preparation. By adjusting these interrelationships, the organization can match the appropriate revenue. In IDS the ability of the high capacity to carry learning for visual demonstration makes neural organizations adaptable and stunning. Although, the time taken to run the model from a big dataset is very large. The aggressive behavior of the IDS can be accurately expected for this.\u003c/p\u003e\n\u003cp\u003eThere are two kinds of interruption discovery frameworks are accessible. Host based Intrusion Detection System (HIDS) which utilizes data accumulated from a solitary host, for example, review trail, log records, framework call groupings and so forth NIDS utilizes the assembled information by breaking down the system organization traffic. HIDS regularly screens and investigations the single host occasions, for the most part the host-based models utilize rule-based example coordinating with approaches [\u003cspan class=\"CitationRef\"\u003e9\u003c/span\u003e][\u003cspan class=\"CitationRef\"\u003e10\u003c/span\u003e]. For every client a profile is made and the HIDS persistently screens and thinks about the current review record and the current client profiles. On the off chance that there is deviation over specific limit esteem then the current movement is considered as a vindictive action. The expanded utilization of the systems and system related assets, brought about expanded number of gadgets and clients associated with the organizations. A Network based Intrusion Detection System (NIDS) screens and examines the organization traffic to shield a framework from network-based malignant exercises. NIDS works at chosen framework on an organization and which examinations network traffic, bundle by parcel to recognize interruption. On the off chance that NIDS is introduced in the organization, it diminishes the responsibility of interruption identification on each individual framework (Figure \u003cspan class=\"InternalRef\"\u003e2\u003c/span\u003e).\u003c/p\u003e\n\u003cdiv class=\"Section2\" id=\"Sec2\"\u003e\n \u003ch2\u003e1.1 Key Highlights\u003c/h2\u003e\n \u003cp\u003eThis paper focus over building a Intrusion detection system which is been integrated with DL could potentially analyze behavior of attacks in which following are some key notes;\u003c/p\u003e\u003cspan\u003e\n \u003cp\u003ea. Intrusion detection system using BPN\u003c/p\u003e\n \u003c/span\u003e \u003cspan\u003e\n \u003cp\u003eb. With collection of system calls that is been passed over this network for analyzing the behavior\u003c/p\u003e\n \u003c/span\u003e \u003cspan\u003e\n \u003cp\u003ec. For improving the optimization power of neural networks, PSO is been utilized\u003c/p\u003e\n \u003c/span\u003e \u003cspan\u003e\n \u003cp\u003ed. The proposed system is compared with other models like ANFIS, F-GNP, and FCM in which the proposed model outperformed with accuracy 96.5%.\u003c/p\u003e\n \u003c/span\u003e\n \u003cp\u003e\u003cstrong\u003eOrganization of paper:\u0026nbsp;\u003c/strong\u003eAs we already come across the overview and the types of IDS in Section 1, rest is as follows; Section 2 depict related works based on IDS integrated with DL then followed by Section 3 with methodology, Section 4 with Implementation and Result, and at last section 5 with conclusion.\u003c/p\u003e\n\u003c/div\u003e"},{"header":"2. Related Works","content":"\u003cp\u003eIn [\u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e11\u003c/span\u003e] the creator proposed an information mining structure for building interruption identification models. The main thought is to process the programs of information mining specifically, grouping, meta-learning, affiliation manages, and continuous scenes to review information for figuring abuse and irregularity location models that precisely catch the behavior (i.e., designs) of interruptions and ordinary exercises. In spite of the fact that, proposed discovery structure can identify a greater level of new and old U2R and PROBING assaults, it missed countless new DOS and R2L assaults. In [\u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e12\u003c/span\u003e], it is generally centered around information mining procedures that are being utilized for the purposes of such, and afterward introduced a groundbreaking thought on how information mining can help IDSs by using bi-clustering as an apparatus to investigate the traffic of network and upgrade IDS\u0026rsquo;s. An investigation of scholastic exploration utilized the accepted standard benchmark information, to improvise the efficiency of interruption identification rate of KDDCup 99. In third International Knowledge Discovery and Data Mining Tools competition, KDDcup 99 was used. The information was generated in such a way as to handle the 1998 DARPA Interruption Location (ID) Assessment Organization's tcpdump information. The challenge was, to make a prescient structure, to arrange the organization associations into 2 classes: Attack or Normal. Assaults are ordered into the ('DoS') Denial of Service, ('U2R') User-to-Root, 'Test', ('R2L') Remote-to-Local, classes. The digging review information for the models of mechanized for (MADAMID) ID was utilized as highlight development structure in KDDCup 99 rivalry [\u003cspan citationid=\"CR13\" class=\"CitationRef\"\u003e13\u003c/span\u003e]. MADAMID yields 41 highlights: initial 9 highlights are fundamental highlights of a bundle, content highlights are 10-22, highlights of traffic are 23-31, and based highlights are 32-41 has. Decisions of the accessible dataset are: full dataset and 10% corresponding information. The nitty gritty assessment after effects of KDDCup 98 and KDDCup 99 test was distributed in [\u003cspan citationid=\"CR14\" class=\"CitationRef\"\u003e14\u003c/span\u003e]. The Third International Knowledge Discovery and Data Mining Tools Competition task continued as the basic work. Machine learning solutions could be found from it. Most of the published works used only 10% of the training and testing data. Very few custom built dataset was used. With the dataset [\u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e17\u003c/span\u003e] of KDDcup 99 a recent survey was conducted on the id of machine learning based. Most of the results published on KDDcup 99 have been utilized for dimensionality reduction in featured engineering methods [\u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e16\u003c/span\u003e]. Most of the newly available machine learning used the same dataset. Few studies have used the custom-built dataset. The outputs are partially comparable to the KDDcup99 contest. In [\u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e18\u003c/span\u003e], by the use of Naive Bayesian network explored the Bayesian networks for ID, in which leaf node = features and root node = class connection. Later, [\u003cspan citationid=\"CR20\" class=\"CitationRef\"\u003e20\u003c/span\u003e] to ID, the application of the Naive Bayes network is identified and by means of detailed experimental analysis, challenge of KDDCup 99 the winning entries with which compared, in \u0026rsquo;Probe\u0026rsquo; and \u0026rsquo;U2R\u0026rsquo; categories better performance is given by a Bayesian network. In [\u003cspan citationid=\"CR21\" class=\"CitationRef\"\u003e21\u003c/span\u003e], on parison-window estimators based method of non-parametric density estimation was studied by the use of Normal distribution and Gaussian kernels. Model temporal and spatial data were used to identify complex anomalies. NIDS proposed a genetic algorithm for this[\u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e22\u003c/span\u003e]. Using System Particle Optimization, Agent Colony Optimization and Colony Clustering [\u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e19\u003c/span\u003e] for ID, a set of intelligence techniques and techniques of synchronization learning overview is provided.\u003c/p\u003e"},{"header":"3. Methodology","content":"\u003cp\u003eFigure \u003cspan class=\"InternalRef\"\u003e3\u003c/span\u003e depict the overall workflow of proposed model in which the system call is collected from the KDD cup 99 dataset are given for the pre-processing stage. Here all the system calls are collected in raw fashion, by using the sliding window mechanism these are pre-processed and are passed for feature selection in which for better optimization we use Particle Swarm Optimization and then passed over to the decision network were using the selected features, neural network (BPN) will process these features into several layer and give the result as system behaves properly or not.\u003c/p\u003e\n\u003cdiv class=\"Section2\" id=\"Sec5\"\u003e\n \u003ch2\u003e3.1 Dataset Description\u003c/h2\u003e\n \u003cp\u003eFor this model for execution, we utilized KDD cup 99 dataset created in MIT Lincoln Laboratories. The Dataset is made by presenting physically produced network-based assaults. Different attacks that can be potentially found in an organization is characterized in a brief form concerning KDD interruption discovery evaluation dataset[\u003cspan class=\"CitationRef\"\u003e6\u003c/span\u003e]. System will be analyzed at different levels such as system accuracy, system ability and cost to differentiate abnormal behavior and normal behavior. IDS can work based on either privileged process behavior or user behavior. The privileged processes have the privileges to access and use system resources. All the normal system calls are gathered in the normal trace step. In abnormal trace step, abnormal system call sequences are gathered. Data set of KDD cup 99 is utilized for collecting abnormal and normal traces. The stide, xlock, ps and login processes sequences of system calls are collected from KDD cup 99 data set. The repeated execution of these processes generates system call sequences which are recorded in separate files. Each trace system call sequence contains ten to thousand system calls. These traces are collected while there are no malicious activities. The examples of abnormal processes are iprcp, buffer overflow, sun sendmailcp etc.\u003c/p\u003e\n \u003cp\u003eAnother example is Syslog attack. It uses the interfaces like syslog which makes buffer overflow in send mail. Intrusion traces contains three sunsendmailcp attacks, forwarding loops five error conditions, two traces of syslog-local attacks, the syslog-remote attacks of two traces, and an attacks of decode two traces. Each trace contains two attributes: process ID and a system call value. The process ID is used to identify the specific system call. An abnormal process will not have the sequences of normal system calls (Figure \u003cspan class=\"InternalRef\"\u003e4\u003c/span\u003e). The current sequence of system calls can be compared with the sequence of normal system calls stored and deviations can be detected[\u003cspan class=\"CitationRef\"\u003e7\u003c/span\u003e][\u003cspan class=\"CitationRef\"\u003e8\u003c/span\u003e].\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"Section2\" id=\"Sec6\"\u003e\n \u003ch2\u003e3.2 Data Pre-processing\u003c/h2\u003e\n \u003cp\u003eAfter collecting the system call sequences of from the active process, the next step is preprocessing of data. The gathered information about system call is basic raw collection data. The techniques used for preprocessing have to be applied on raw data to make the data set into processing dataset. A unique number will be assigned to each and every system call name. For instance, 8 for open, 9 for close, 74 for mmap etc. The unique numbering will make it is easy to access the system call, reduces data complexity and convenient format for processing. With proper sliding window mechanism, long system call sequence numbers can be processed. The normal behavioral data base uses the window size of 3. For example, the normal behavior database can be created from the following system call sequence Open, read, mmap, mmap, open, read, close for the given sequence, the system calls will be put in position 1, position 2 and position 3 as shown in below table. The window size decides the pairs generated. Table \u003cspan class=\"InternalRef\"\u003e1\u003c/span\u003e depict the sequence of system call in proposed system.\u003c/p\u003e\n \u003cdiv class=\"gridtable\"\u003e\u003ctable border=\"1\" id=\"Tab1\"\u003e\n \u003ccaption language=\"En\"\u003e\n \u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e\n \u003cdiv class=\"CaptionContent\"\u003e\n \u003cp\u003eSystem call sequence\u003c/p\u003e\n \u003c/div\u003e\n \u003c/caption\u003e\n \u003cthead\u003e\n \u003ctr\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003eCurrent\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003ePosition1\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003ePosition2\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003ePosition3\u003c/p\u003e\n \u003c/th\u003e\n \u003c/tr\u003e\n \u003c/thead\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eClose\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eClose\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eClose\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003ctd align=\"left\"\u003e\u0026nbsp;\u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n \u003c/table\u003e\n \u003c/div\u003e\n \u003cp\u003eBy analyzing the data set it is found that certain system calls are executed frequently. These systems call executions may be followed by different system calls. For example, the read is followed by different system calls and executed two times. Therefore, all system calls are recorded first and then, expanded the database for different sequences. The expanded format is given in the following Table \u003cspan class=\"InternalRef\"\u003e2\u003c/span\u003e.\u003c/p\u003e\n \u003cdiv class=\"gridtable\"\u003e\u003ctable border=\"1\" id=\"Tab2\"\u003e\n \u003ccaption language=\"En\"\u003e\n \u003cdiv class=\"CaptionNumber\"\u003eTable 2\u003c/div\u003e\n \u003cdiv class=\"CaptionContent\"\u003e\n \u003cp\u003eExpanded system call\u003c/p\u003e\n \u003c/div\u003e\n \u003c/caption\u003e\n \u003cthead\u003e\n \u003ctr\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003eCurrent\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003ePosition1\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003ePosition2\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003ePosition3\u003c/p\u003e\n \u003c/th\u003e\n \u003c/tr\u003e\n \u003c/thead\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e, close\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eRead\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e, close\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eMmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003emmap\u003csub\u003e1\u003c/sub\u003e, open\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eOpen\u003csub\u003e1\u003c/sub\u003e, read\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003eClose\u003csub\u003e1\u003c/sub\u003e, read\u003csub\u003e1\u003c/sub\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n \u003c/table\u003e\n \u003c/div\u003e\n \u003cp\u003eUsing the sliding window, many system call sequences are produced and stored in database. After data base is preprocessed from raw information, normal behavior rule can be easily formed from this data set.\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"Section2\" id=\"Sec7\"\u003e\n \u003ch2\u003e3.3 Particle Swarm Optimization\u003c/h2\u003e\n \u003cp\u003eHere once it is normalized, these are now passed over to feature selection process where you naturally or physically select those highlights which contribute most to your expectation variable or yield in which you are keen on. So, for that PSO is used here for feature extraction. PSO is an equal estimation, which has the advantages of straightforward execution, high exactness and quick assembly[\u003cspan class=\"CitationRef\"\u003e19\u003c/span\u003e]. To track down the best arrangement, PSO instates some irregular arrangements in arrangement space, these arrangements are a few particles, where characterize the molecule speed \u003cem\u003ev\u003c/em\u003e\u003csub\u003e\u003cem\u003ei\u003c/em\u003e\u003c/sub\u003e and the molecule position \u003cem\u003ex\u003c/em\u003e\u003csub\u003e\u003cem\u003ei\u003c/em\u003e\u003c/sub\u003e. In the meantime, use the capacity of health to determine if the circumstances of the particles are ideal, use \u003cem\u003epbest\u003c/em\u003e and \u003cem\u003egbest\u003c/em\u003e to capture the individual best circumstances and social opportunity independently. For every particle, note its well-being, it will also be \u003cem\u003epbest\u003c/em\u003e if it is better contrasted with \u003cem\u003epbest\u003c/em\u003e, and it will be like \u003cem\u003egbest\u003c/em\u003e expect better contrasted with \u003cem\u003egbest\u003c/em\u003e, update the speed and location of the molecule. The speed of molecules and position update rules are according to the accompaniment;\u003c/p\u003e\n \u003cdiv class=\"Equation\" id=\"Equ1\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ1\" name=\"EquationSource\"\u003e$${v}_{i}=w{v}_{i}+{c}_{1}\\times rand\\left(\\right)\\times \\left({ pbest }_{i}-{x}_{i}\\right)+{c}_{2}\\times rand\\left(\\right)\\times ({ gbest }_{i}-{x}_{i}) {x}_{i}={x}_{i}+{v}_{i}$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e1\u003c/div\u003e\n \u003c/div\u003e\n \u003cp\u003ewhere \u003cem\u003ev\u003c/em\u003e\u003csub\u003e\u003cem\u003ei\u003c/em\u003e\u003c/sub\u003e is the speed of the molecule, \u003cem\u003ew\u003c/em\u003e is inactivity weight, \u003cem\u003erand()\u003c/em\u003e is an irregular worth somewhere in the range of 0 and \u003cem\u003ec\u003c/em\u003e\u003csub\u003e\u003cem\u003e1\u003c/em\u003e\u003c/sub\u003e and \u003cem\u003ec\u003c/em\u003e\u003csub\u003e\u003cem\u003e2\u003c/em\u003e\u003c/sub\u003e is the current situation of the molecule \u003cem\u003ec\u003c/em\u003e\u003csub\u003e\u003cem\u003e1\u003c/em\u003e\u003c/sub\u003e and \u003cem\u003ec\u003c/em\u003e\u003csub\u003e\u003cem\u003e2\u003c/em\u003e\u003c/sub\u003e are speed increase factor. If the velocity or circumstance of the particles exceeds the degree of stroke, it will be defined as the most limiting velocity or the circumstance of the cutoff. At the point where the molecule has been reinvigorated, it will keep reheating until the best game plan is found. Regularly finding the best position or appearing at the most remarkable number of cycles will halt the demand. In BPN, the number of concealed core layer points affects the generation of the independent learning stage and the fine-tuning of coordinated learning stage. Along these lines, the quantity of covered up layer hubs in the profound adapting should be enhanced by PSO calculation to improve the exhibition of the organization.\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"Section2\" id=\"Sec8\"\u003e\n \u003ch2\u003e3.4 Back Propagation Network\u003c/h2\u003e\n \u003cp\u003eLearn an example for back propagation network. When you provide examples of networking algorithm and it changes the weight of the network, for a particular input the required output will given when completed the training. For simple pattern identification and mapping tasks Back Propagation Networks can be used. As mentioned now, you need to give a particular input in order to get the desired output. It is mentioned in Figure \u003cspan class=\"InternalRef\"\u003e5\u003c/span\u003e.\u003c/p\u003e\n \u003cp\u003eIf it is the first pattern to the network, we would like the output to be 0 1 as shown in Figure 6. (yellow line =1 and black= 0 like previous examples). Training Pair means the input and its corresponding target.\u003c/p\u003e\n \u003cp\u003eOnce the network is trained, it will provide the desired output for any of the input patterns.\u003c/p\u003e\n \u003cp\u003eIf the network is trained once then it will yield the required output to any input. Now let\u0026apos;s see how it goes. All weights must first initialize the network by giving small random numbers (between -1 and 1). Now you need to perform the forward pass (give the input and calculate the output). The calculations will give you a different output than you need (the target), all weights will be random. Then each neuron\u0026rsquo;s error is calculated. Here, Actual Output = Target (i.e. what you actually get - what you want). The error get from the output is then used for changing the weight. Then we can reduce the error part. By this way each neuron\u0026rsquo;s output will get nearer to required output value. It is known as reverse pass. This step is iterated until the error is minimal.\u003c/p\u003e\n \u003cp\u003e\u003cb\u003eAlgorithm1: BPN\u003c/b\u003e\u003c/p\u003e\u003cp\u003e1. Give the information and take the yield from the organization. Since the main weight is irregular numbers, hence recollect that the principal yield can be anything.\u003c/p\u003e\u003cp\u003e2. Presently we need to address the blunder of neuron B. Blunder is the thing that you need \u0026ndash; What you really get, all in all: ErrorB = OutputB (1-OutputB) (TargetB \u0026ndash; OutputB) The \u0026quot;Yield (1-Output)\u0026quot; term is fundamental in the condition due to the Sigmoid Function \u0026ndash; in the event that we were just utilizing a limit neuron it would simply be (Target - Output).\u003c/p\u003e\u003cp\u003e3. Presently you need to alter the weight. Let WAB = introductory weight and W+AB = trained (new) weight. W+AB = WAB + (ErrorB x OutputA). Notice that it is the yield of the interfacing (neuron A) we use (not B). This is the way we update every one of the heaps on the yield layer.\u003c/p\u003e\u003cp\u003e4. Figure the Errors for the secret layer neurons We can\u0026apos;t ascertain it straightforwardly from the yield layer since we don\u0026apos;t have an objective. That is the reason this calculation is known by that name). This is finished by taking mistakes from the need yield neurons and by means of the heap, running them back to get errors of covered up layer. For model assuming neuron An is associated as to B and C as appeared, for creating a blunder for A we need take the blunders from B and C. ErrorA = Output A (1 - Output A) (ErrorC WAC + ErrorB WAB) Again, the factor \u0026quot;Yield (1 - Output)\u0026quot; is available due to the sigmoid crushing capacity.\u003c/p\u003e\u003cp\u003e5. Assuming you get the mistake for the hidden layer neurons once, the subsequent stage to change the secret layer weight. Consequently we can rehash this strategy and make it workable for quite a few layered networks. Once in a while there might be questions about its capacity. It shows the estimation of a FCN. It comprises, number of data sources =2, covered up layer neurons = 3 and yield = 2. Where w + = new and recalculated weight, w (without addendum) =old weight. The opposite interaction can be determined similarly.\u003c/p\u003e\n\u003c/div\u003e"},{"header":"4.\tImplementation And Results","content":"\u003cp\u003eInitially this model is implemented over wamp server and are run in python environment over the i5 Core intel system. The proposed model is evaluated under two performance measure such as Detection Rate (DR) and False Alarm Rate (FAR), also it is compared with other models such as ANFIS, F-GNP and FCM.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ea. Detection Rate\u003c/strong\u003e: Detection rate indicates, among all attack data, the percentage of detected attack, and is provided as,\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eDR: TP/ (TP + TN) *100\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eb. False Alarm Rate\u003c/strong\u003e: False Alarm Rate is otherwise known as false positive(FP). It is the proportion that normal data is falsely detected as attack behavior. Accuracy is classified as: true positive(TP) and true negative(TN).It is the proportion of correctly classified data.\u003c/p\u003e\n\u003ctable border=\"1\" id=\"Tab3\"\u003e\n \u003ccaption language=\"En\"\u003e\n \u003cdiv class=\"CaptionNumber\"\u003eTable 3\u003c/div\u003e\n \u003cdiv class=\"CaptionContent\"\u003e\n \u003cp\u003ePerformance Measure\u003c/p\u003e\n \u003c/div\u003e\n \u003c/caption\u003e\n \u003cthead\u003e\n \u003ctr\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003eModels\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003eFAR\u003c/p\u003e\n \u003c/th\u003e\n \u003cth align=\"left\"\u003e\n \u003cp\u003eDR (%)\u003c/p\u003e\n \u003c/th\u003e\n \u003c/tr\u003e\n \u003c/thead\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003eANFIS\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"char\"\u003e\n \u003cp\u003e\u003cstrong\u003e3.4\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003e92\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003eF-GNP\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"char\"\u003e\n \u003cp\u003e\u003cstrong\u003e1.9\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003e80\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003eFCM\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"char\"\u003e\n \u003cp\u003e\u003cstrong\u003e2.4\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003e85\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003eBPN\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"char\"\u003e\n \u003cp\u003e\u003cstrong\u003e4.4\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd align=\"left\"\u003e\n \u003cp\u003e\u003cstrong\u003e96.5%\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003eTable \u003cspan class=\"InternalRef\"\u003e3\u003c/span\u003e shows the comparison of various systems like ANFIS, F-GNP and FCM with our system under the performance measure DR and FAR. The FAR of our system is 4.4 while it is 1.9 for F-GNP. While taking DR our system shows a detection rate of 96.5% which is better than all the other compared models.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eANFIS:\u0026nbsp;\u003c/strong\u003eThe ANFIS structure maps contributions through input enrollment works and related boundaries, and afterward through yield participations and related boundaries to yields. During the learning interaction, the boundaries related with enrollment capacities changes. An incline vector empowers the figuring of these limits, giving an extent of how well the FIS models the data/yield data for a given game plan of limits. In the wake of procuring the tendency vector, any of the couple of smoothing out timetables could be applied to change the limits for reducing some mix-up measure. This learning method works correspondingly as that of neural associations. When appeared differently in relation to the generally FIS, ANFIS is really astounding. This makes the fuzzy system to acquire from the data they model (Figure \u003cspan class=\"InternalRef\"\u003e7\u003c/span\u003e).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eF-GNP:\u0026nbsp;\u003c/strong\u003eGNP has been supportive of acted like one of the transformative calculations[\u003cspan class=\"CitationRef\"\u003e17\u003c/span\u003e]. It was utilized to programmed program age for efficient specialist practices. GNP is addressed by chart structures which comprise of three kind hubs, i.e., start hub, judgment hub and preparing hub. These hubs are associated with one another as coordinated diagram structures which give more benefits, i.e., reusability of hubs and flexibility to mostly discernible Markov choice issues. GNP has been effectively applied to the issues in unique conditions, for example, lift administrative control frameworks, stock exchanging markets and tile world (Figure \u003cspan class=\"InternalRef\"\u003e8\u003c/span\u003e).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFCM:\u0026nbsp;\u003c/strong\u003eCorresponding to every data point via assigning membership value to every cluster this algorithm works. On the distance between the data point and the cluster center it depends. Towards the particular cluster center gives the more is its membership when more the data is closer to cluster center. i.e, each data point\u0026rsquo;s sum of membership = 1. According to formula, cluster centers are updated after performing each iteration membership. It is shown in Figure \u003cspan class=\"InternalRef\"\u003e9\u003c/span\u003e.\u003c/p\u003e\n\u003cp\u003eFigure \u003cspan class=\"InternalRef\"\u003e10\u003c/span\u003e and \u003cspan class=\"InternalRef\"\u003e11\u003c/span\u003e depict the detection rate and FAR of the proposed system while comparing it with other methods.\u003c/p\u003e\n\u003cp\u003eFigure \u003cspan class=\"InternalRef\"\u003e12\u003c/span\u003ea, b shows the starting snapshot of the proposed system in which we have several modules and each module contain its corresponding operation.\u003c/p\u003e\n\u003cp\u003eFigure \u003cspan class=\"InternalRef\"\u003e13\u003c/span\u003ea, b depicts the initializing the starting module and once the KDD dataset is loaded then a pop displaying data loaded successfully. Figure \u003cspan class=\"InternalRef\"\u003e14\u003c/span\u003e depict the pre-processing stage of KDD. Figure \u003cspan class=\"InternalRef\"\u003e15\u003c/span\u003e shows the PSO process after pre-processing stage. Figure \u003cspan class=\"InternalRef\"\u003e16\u003c/span\u003e shows the BPN training process where the inputs are given before optimizing it and are entirely process to gain the final report. And once the training done, then a pop will be displayed. Figure \u003cspan class=\"InternalRef\"\u003e17\u003c/span\u003e depict the overall view of BPN outperforming than other existing system in a graphical representation.\u003c/p\u003e"},{"header":"5. Conclusion","content":"\u003cp\u003eFrom this, it is clear that in today\u0026rsquo;s world, how everyone gives much priority to the \u0026ldquo;security\u0026rdquo; and for that so much efficient models been released every day in much different forms. So, like that here we build an effective IDS using BPN in which system calls are collected from KDD cup 99 and are pre-processed using the sliding window and finally gave to neural network for better analysis and finally predict that, if the system behaves in normal or abnormal fashion. Also, we compared our system with other existing models under detection rate and FAR in which our system performs better with 96.5%. In future many other advance optimization techniques can be used for boosting the neural network, also other neural networks can be brought up by various researchers who can dig dive by getting inspired by this paper.\u003c/p\u003e"},{"header":"Abbreviations","content":"\u003ctable border=\"1\" cellpadding=\"0\" cellspacing=\"0\" width=\"0\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eDL\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eDeep Learning\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eBPN\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eBack Propagation Network\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eIDS\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eIntrusion Detection System\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eNIDS\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eNetwork Intrusion Detection System\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eHIDS\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eHost based Intrusion Detection System\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eDR\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eDetection Rate\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eFAR\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eFalse Alarm Rate\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eU2L\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eUser to Local\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eR2L\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eRoot to Local\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eDoS\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eDenial of Service\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003ePSO\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eParticle Swarm Optimization\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eNN\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eNeural Network\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eANFIS\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eAdaptive Neuro Fuzzy Inference System\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eF-GNP\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eFuzzy Graph Neural Process\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" width=\"12.5%\"\u003e\n \u003cp\u003eFCM\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" width=\"87.5%\"\u003e\n \u003cp\u003eFuzzy C Mean Clustering\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eFunding:\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe authors did not receive financial support from any organization for the submitted work.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eConflicts of interest/Competing interests:\u003c/strong\u003e The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eAvailability of data and material:\u003c/strong\u003e \u003cp\u003e\u0026lsquo;Not applicable\u0026rsquo;, \u003cstrong\u003eAuthors\u0026rsquo; contributions:\u003c/strong\u003e \u0026lsquo;Not applicable\u0026rsquo;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eCode availability:\u003c/strong\u003e \u0026lsquo;Not applicable\u0026rsquo;, \u003cstrong\u003eConsent to participate:\u003c/strong\u003e \u0026lsquo;Not applicable\u0026rsquo;\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eEthics approval:\u003c/strong\u003e Compliance with Ethical Standards.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eConsent for publication:\u003c/strong\u003e Authors give consent to Soft Computing Journal to publish their article.\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\u003cli\u003e\u003cspan\u003eElmasry W, Akbulut A, Abdul Halim Zaim (2021) A Design of an Integrated Cloud-based Intrusion Detection System with Third Party Cloud Service. Open Computer Science 11(1):365\u0026ndash;379\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eSalvatore Pontarelli G, Bianchi S, Teofili Traffic-aware Design of a High Speed FPGA Network Intrusion Detection System.Digital Object Identifier10.1109/TC.2012.105, IEEE TRANSACTIONS ON COMPUTERS.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eElrawy MF, Awad AI, Hesham FAH (2018) Intrusion detection systems for IoT-based smart environments: a survey. Journal of Cloud Computing 7(1):1\u0026ndash;20\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eThilagam T, Aruna R (2021) \"Intrusion detection for network based cloud computing by custom RC-NN and optimization.\"ICT Express\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eIdhammad M, Afdel K, Mustapha Belouch (2018) Distributed intrusion detection system for cloud environments based on data mining techniques. Procedia Computer Science 127:35\u0026ndash;41\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDeshpande P, Sharma SC, Peddoju SK, Junaid S (2018) HIDS: A host based intrusion detection system for cloud computing environment. International Journal of System Assurance Engineering and Management 9(3):567\u0026ndash;576\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eApurva S, Patil, Dipak R Patil\u0026ldquo; Offline host based intrusion detection based on analysis of system calls\u0026rdquo;, International Journal for Research in Engineering Application \u0026amp; Management (IJREAM) ISSN: 2494- 9150, Vol-02, Issue 04, July 2016\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eRamprakash P, Sakthivadivel M, Krishnaraj N, Ramprasath J \u0026ldquo;Host-based intrusion detection system using sequence of system calls\u0026rdquo;, International Journal of Engineering and Management Research, Volume-4, Issue-2, April-2014, ISSN No.: 2250-0758\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eSekhar R, Sasirekha K, Raja PS, Thangavel K (2021) A novel GPU based intrusion detection system using deep autoencoder with Fruitfly optimization. SN Applied Sciences 3(6):1\u0026ndash;16\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eWei P, Li Y, Zhang Z, Hu T, Li Z, Liu D (2019) An optimization method for intrusion detection classification model based on deep belief network. IEEE Access 7:87593\u0026ndash;87605\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eVinayakumar R, Alazab M, Soman KP, Poornachandran P (2019) Ameer Al-Nemrat, and Sitalakshmi Venkatraman. \"Deep learning approach for intelligent intrusion detection system. IEEE Access 7:41525\u0026ndash;41550\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKim J, Kim J, Kim H, Shim M, Choi E (2020) \"CNN-based network intrusion detection against denial-of-service attacks.\" \u003cem\u003eElectronics\u003c/em\u003e 9, no. 6 : 916\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eAmudha P, Karthik S, Sivakumari S (2015) \"A hybrid swarm intelligence algorithm for intrusion detection using significant features.\" \u003cem\u003eThe Scientific World Journal\u003c/em\u003e (2015)\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eStaudemeyer RC (2015) Applying long short-term memory recurrent neural networks to intrusion detection. South African Computer Journal 56(1):136\u0026ndash;154\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHuang X (2021) \"Network Intrusion Detection Based on an Improved Long-Short-Term Memory Model in Combination with Multiple Spatiotemporal Structures.\" \u003cem\u003eWireless Communications and Mobile Computing\u003c/em\u003e (2021)\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eTan X, Su S, Zuo Z, Guo X, Sun X (2019) \"Intrusion detection of UAVs based on the deep belief network optimized by PSO.\" \u003cem\u003eSensors\u003c/em\u003e 19, no. 24 : 5529\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eAzad C (2017) \"Fuzzy min\u0026ndash;max neural network and particle swarm optimization based intrusion detection system. Microsyst Technol 23(4):907\u0026ndash;918\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eVenkatraman S, Alazab M (2018) \"Use of data visualisation for zero-day malware detection.\" \u003cem\u003eSecurity and Communication Networks\u003c/em\u003e (2018)\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKunhare N, Tiwari R, Dhar J (2020) \"Particle swarm optimization and feature selection for intrusion detection system.\" \u003cem\u003eSādhanā\u003c/em\u003e 45, no. 1 : 1-14\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eLiu J, Yang D, Lian M, Li M (2021) Research on Intrusion Detection Based on Particle Swarm Optimization in IoT. IEEE Access 9:38254\u0026ndash;38268\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eSolanki M, Dhamdhere V (2015) \u0026rdquo;Intrusion detection system using means of data mining by using c 4.5 algorithm\u0026rdquo;,International Journal of Application or Innovation in Engineering \u0026amp; Management, Volume 4, Issue 5,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eYin C, Zhu Y, Fei J, He X (2017) A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks. IEEE Access 5:21954\u0026ndash;21961\u003c/span\u003e\u003c/li\u003e\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"soft-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"soco","sideBox":"Learn more about [Soft Computing](https://www.springer.com/journal/500)","snPcode":"500","submissionUrl":"https://submission.nature.com/new-submission/500/3","title":"Soft Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Back Propagation Network, Intrusion Detection System, Neural Network, Particle Swarm Optimization, System Calls","lastPublishedDoi":"10.21203/rs.3.rs-1298053/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-1298053/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003e\u003cem\u003eThe usage of internet is getting increased in all aspect, like from building various models that are fully connect with internet to the usage of digital media for 24/7. As this is rising in a way, on the other side the concern about “data security” is raising and everybody’s information needs to be protected from any other attacks or can say there shouldn’t be no data leakage. So, for detecting these attacks, intrusion detection system is placed. But placing this traditional Intrusion Detection System (IDS) will increase the concerns of security even more, so to amp the process integration of latest technology such deep learning comes in action. Thereby this paper proposes an IDS using Back-propagation Network (BPN) where intrusions are identified based on the system calls that we collected in the dataset KDD cup 99. Also, to increase the optimization of neural network, we used Particle Swarm Optimization (PSO) thereby increase the accurate detection of the system saying if that is normal or abnormal in behavior. We evaluate our proposed model with other methods like ANFIS, F-GNP, FCM in which the proposed model gives 96.5% accurate detection.\u003c/em\u003e\u003c/p\u003e","manuscriptTitle":"Optimization of BPN Parameters Using PSO for Intrusion Detection in Cloud Environment","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2022-02-03 20:45:34","doi":"10.21203/rs.3.rs-1298053/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"editorInvitedReview","content":"","date":"2022-02-02T04:14:46+00:00","index":0,"fulltext":""},{"type":"reviewersInvited","content":"","date":"2022-02-01T07:06:38+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2022-01-31T05:42:34+00:00","index":"","fulltext":""},{"type":"submitted","content":"Soft Computing","date":"2022-01-26T02:04:40+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"soft-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"soco","sideBox":"Learn more about [Soft Computing](https://www.springer.com/journal/500)","snPcode":"500","submissionUrl":"https://submission.nature.com/new-submission/500/3","title":"Soft Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"adfac8bd-46c1-4f3e-b7dc-89bebfc2a784","owner":[],"postedDate":"February 3rd, 2022","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"published-in-journal","subjectAreas":[],"tags":[],"updatedAt":"2023-10-16T21:27:50+00:00","versionOfRecord":{"articleIdentity":"rs-1298053","link":"https://doi.org/10.1007/s00500-023-08737-1","journal":{"identity":"soft-computing","isVorOnly":false,"title":"Soft Computing"},"publishedOn":"2023-06-21 21:16:56","publishedOnDateReadable":"June 21st, 2023"},"versionCreatedAt":"2022-02-03 20:45:34","video":"","vorDoi":"10.1007/s00500-023-08737-1","vorDoiUrl":"https://doi.org/10.1007/s00500-023-08737-1","workflowStages":[]},"version":"v1","identity":"rs-1298053","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-1298053","identity":"rs-1298053","version":["v1"]},"buildId":"rHA-KDH7Qsr4HCuvH75dn","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.

Source provenance

europepmc
last seen: 2026-05-19T01:45:01.086888+00:00