<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Comput. Neurosci.</journal-id>
<journal-title>Frontiers in Computational Neuroscience</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Comput. Neurosci.</abbrev-journal-title>
<issn pub-type="epub">1662-5188</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.3389/fncom.2023.1079483</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Neuroscience</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Kohonen neural network and symbiotic-organism search algorithm for intrusion detection of network viruses</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name><surname>Zhou</surname> <given-names>Guo</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="corresp" rid="c001"><sup>&#x002A;</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Miao</surname> <given-names>Fahui</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Tang</surname> <given-names>Zhonghua</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<xref ref-type="aff" rid="aff3"><sup>3</sup></xref>
</contrib>
<contrib contrib-type="author" corresp="yes">
<name><surname>Zhou</surname> <given-names>Yongquan</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<xref ref-type="aff" rid="aff3"><sup>3</sup></xref>
<xref ref-type="corresp" rid="c002"><sup>&#x002A;</sup></xref>
<uri xlink:href="http://loop.frontiersin.org/people/1586299/overview"/>
</contrib>
<contrib contrib-type="author">
<name><surname>Luo</surname> <given-names>Qifang</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
</contrib>
</contrib-group>
<aff id="aff1"><sup>1</sup><institution>Department of Science and Technology Teaching, China University of Political Science and Law</institution>, <addr-line>Beijing</addr-line>, <country>China</country></aff>
<aff id="aff2"><sup>2</sup><institution>College of Artificial Intelligence, Guangxi University for Nationalities</institution>, <addr-line>Nanning</addr-line>, <country>China</country></aff>
<aff id="aff3"><sup>3</sup><institution>Guangxi Key Laboratories of Hybrid Computation and Integrated Circuit (IC) Design Analysis</institution>, <addr-line>Nanning</addr-line>, <country>China</country></aff>
<author-notes>
<fn fn-type="edited-by"><p>Edited by: Tien-Loc Le, Sejong University, Republic of Korea</p></fn>
<fn fn-type="edited-by"><p>Reviewed by: Jinjing Shi, Central South University, China; Ramalingam Sakthivel, Chungbuk National University, Republic of Korea; Ali Wagdy Mohamed, Cairo University, Egypt</p></fn>
<corresp id="c001">&#x002A;Correspondence: Guo Zhou, <email>zhouguo@cupl.edu.cn</email></corresp>
<corresp id="c002">Yongquan Zhou, <email>zhouyongquan@gxun.edu.cn</email></corresp>
</author-notes>
<pub-date pub-type="epub">
<day>22</day>
<month>02</month>
<year>2023</year>
</pub-date>
<pub-date pub-type="collection">
<year>2023</year>
</pub-date>
<volume>17</volume>
<elocation-id>1079483</elocation-id>
<history>
<date date-type="received">
<day>25</day>
<month>10</month>
<year>2022</year>
</date>
<date date-type="accepted">
<day>06</day>
<month>02</month>
<year>2023</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#x00A9; 2023 Zhou, Miao, Tang, Zhou and Luo.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Zhou, Miao, Tang, Zhou and Luo</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p></license>
</permissions>
<abstract>
<sec>
<title>Introduction</title>
<p>The development of the Internet has made life much more convenient, but forms of network intrusion have become increasingly diversified and the threats to network security are becoming much more serious. Therefore, research into intrusion detection has become very important for network security.</p>
</sec>
<sec>
<title>Methods</title>
<p>In this paper, a clustering algorithm based on the symbiotic-organism search (SOS) algorithm and a Kohonen neural network is proposed.</p>
</sec>
<sec>
<title>Results</title>
<p>The clustering accuracy of the Kohonen neural network is improved by using the SOS algorithm to optimize the weights in the Kohonen neural network.</p>
</sec>
<sec>
<title>Discussion</title>
<p>Our approach was verified with the KDDCUP99 network intrusion data. The experimental results show that SOS-Kohonen can effectively detect intrusion. The detection rate was higher, and the false alarm rate was lower.</p>
</sec>
</abstract>
<kwd-group>
<kwd>intrusion detection</kwd>
<kwd>symbiotic-organism search algorithm</kwd>
<kwd>Kohonen neural network</kwd>
<kwd>detection rate</kwd>
<kwd>false alarm rate</kwd>
</kwd-group>
<contract-sponsor id="cn001">National Natural Science Foundation of China<named-content content-type="fundref-id">10.13039/501100001809</named-content></contract-sponsor><contract-sponsor id="cn002">National Natural Science Foundation of China<named-content content-type="fundref-id">10.13039/501100001809</named-content></contract-sponsor>
<counts>
<fig-count count="6"/>
<table-count count="8"/>
<equation-count count="16"/>
<ref-count count="35"/>
<page-count count="15"/>
<word-count count="6461"/>
</counts>
</article-meta>
</front>
<body>
<sec id="S1" sec-type="intro">
<title>1. Introduction</title>
<p>With the rapid spread of the Internet, there has also been a rapid development of online systems for shopping, banking, making payments, stock trading, and so on. However, due to the openness of the network, forms of network intrusion are becoming increasingly diversified, so that networks and systems are experiencing ever more serious threats. Therefore, detecting network intrusion has become a critical issue in network security. In recent years, increasing attention has been paid by scholars all over the world to intrusion detection. The aim is to identify any behavior that could compromise the integrity, confidentiality, or availability of the system. It can be defined as identifying the people accessing a computer system (<xref ref-type="bibr" rid="B28">Shitharth and Winston, 2017</xref>). Current methods of network intrusion detection can be divided into two categories: misuse intrusion detection and abnormal intrusion detection. The capability of misuse intrusion detection mainly depends on the completeness of the detection knowledge base. Its shortcoming is that it cannot find unknown forms of intrusion. Abnormal intrusion detection is based on identifying a difference between the detected and acceptable behavior.</p>
<p>Due to their continuous development, various swarm intelligence algorithms have been applied to intrusion detection, such as the genetic algorithm (<xref ref-type="bibr" rid="B21">Mabu et al., 2011</xref>), immune algorithm (<xref ref-type="bibr" rid="B35">Zhang et al., 2014</xref>), ant colony optimization (<xref ref-type="bibr" rid="B9">Feng et al., 2014</xref>), and so on. However, as the &#x201C;no free lunch&#x201D; theorem (<xref ref-type="bibr" rid="B31">Wolpert and Macready, 1997</xref>) argues, none of these group intelligence algorithms is suitable for detecting all forms of intrusion. Thus, finding a better algorithm is still a hot topic for scholars in various countries.</p>
<p>In recent years, various meta-heuristic algorithms have been proposed, such as the crow search algorithm (<xref ref-type="bibr" rid="B3">Askarzadeh, 2016</xref>; <xref ref-type="bibr" rid="B15">Hussien et al., 2021</xref>), monarch butterfly optimization (<xref ref-type="bibr" rid="B29">Wang et al., 2019</xref>), lightning search algorithm (<xref ref-type="bibr" rid="B25">Shareef et al., 2015</xref>; <xref ref-type="bibr" rid="B1">Abualigah et al., 2021</xref>), water evaporation optimization (<xref ref-type="bibr" rid="B17">Kaveh and Bakhshpoori, 2016</xref>), Kohonen neural network (<xref ref-type="bibr" rid="B30">Wehrens and Buydens, 2007</xref>; <xref ref-type="bibr" rid="B6">De Almeida et al., 2013</xref>), symbiotic-organism search (SOS) algorithm (<xref ref-type="bibr" rid="B5">Cheng and Prayogo, 2014</xref>; <xref ref-type="bibr" rid="B8">Ezugwua and Prayogo, 2019</xref>; <xref ref-type="bibr" rid="B4">Chakraborty et al., 2022</xref>), bat algorithm (BA) (<xref ref-type="bibr" rid="B32">Xinshe, 2010</xref>; <xref ref-type="bibr" rid="B26">Shehab et al., 2022</xref>), cuckoo algorithm (CS) (<xref ref-type="bibr" rid="B34">Yang and Deb, 2009</xref>), flower pollination algorithm (FPA) (<xref ref-type="bibr" rid="B33">Yang, 2012</xref>; <xref ref-type="bibr" rid="B10">Fouad and Gao, 2019</xref>), grey wolf optimizer (GWO) (<xref ref-type="bibr" rid="B22">Mirjalili et al., 2014</xref>), particle swarm algorithm (PSO) (<xref ref-type="bibr" rid="B19">Kennedy and Eberhart, 1995</xref>; <xref ref-type="bibr" rid="B16">Jordehi and Jasni, 2015</xref>), Harris hawk optimization(<xref ref-type="bibr" rid="B14">Hussien et al., 2022</xref>), Quantum-inspired deep neural networks (<xref ref-type="bibr" rid="B27">Shi et al., 2021</xref>), Gaining&#x2013;sharing knowledge based algorithm (<xref ref-type="bibr" rid="B24">Mohamed et al., 2020</xref>) and so on.</p>
<p>This paper proposes a clustering algorithm based on the SOS algorithm and a Kohonen neural network. The clustering accuracy of Kohonen neural network was improved by using the SOS algorithm to optimize the weights of the Kohonen neural network. SOS-Kohonen was tested with the KDDCUP99 network intrusion data. The experimental results show that it can effectively detect intrusion detection. Compared to other standard methods, the detection rate was higher and the false alarm rate was lower.</p>
<p>The remainder of the paper is organized as follows. Section 2 describes the structure of a Kohonen neural network. Section 3 introduces a basic SOS algorithm. Section 4 considers the use of the SOS-Kohonen algorithm for intrusion detection. Section 5 describes the data preprocessing method. The simulation experiments and results are presented in Sections 6, 7 concludes and discusses future work.</p>
</sec>
<sec id="S2">
<title>2. Kohonen neural network</title>
<p>Finnish professor Teuvo Kohonen proposed an unsupervised self-organizing competitive neural network called a Kohonen neural network. It can achieve automatic clustering by using a self-organizing feature mapping to adjust network weights. A Kohonen neural network (<xref ref-type="bibr" rid="B6">De Almeida et al., 2013</xref>) consists of two feedforward layers, namely an input layer and an output layer. The input layer is mapped into a two-dimensional response mesh in the output layer based on weights. The topology of a Kohonen neural network is shown in <xref ref-type="fig" rid="F1">Figure 1</xref>.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption><p>Structure of a Kohonen neural network.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fncom-17-1079483-g001.tif"/>
</fig>
<p>In a Kohonen neural network, the Euclidean distance of each neuron is obtained by calculating the input eigenvector for the corresponding output layer. The neuron with the smallest Euclidean distance is the superior neuron, and its connection weights are adjusted to make it closer to the original input vector. The area adjacent to the winning neuron is also adjusted by the connection weight to make it closer to the input vector.</p>
<p>In the training phase, each input vector <italic>X</italic><sub><italic>s</italic></sub> is input into the network, and only those winning neurons closest to the current weight vector of the input receive a corresponding stimulus. The pattern vector <italic>X</italic><sub><italic>s</italic></sub> is calculated as the minimum Euclidean distance from the selected winning neurons:</p>
<disp-formula id="S2.E1">
<label>(1)</label>
<mml:math id="M1">
<mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>c</mml:mi>
</mml:mrow>
<mml:mo>&#x2190;</mml:mo>
<mml:mrow>
<mml:munder>
<mml:mo movablelimits="false">min</mml:mo>
<mml:mi>j</mml:mi>
</mml:munder>
<mml:mrow>
<mml:mo>{</mml:mo>
<mml:mrow>
<mml:munder>
<mml:mo largeop="true" movablelimits="false" symmetric="true">&#x2211;</mml:mo>
<mml:mi>i</mml:mi>
</mml:munder>
<mml:msup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:msup>
</mml:mrow>
<mml:mo>}</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo rspace="12.5pt">,</mml:mo>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mrow>
<mml:mi>N</mml:mi>
<mml:mo>&#x00D7;</mml:mo>
<mml:mi>N</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>where <italic>c</italic> represents the winning neuron and <italic>x</italic><sub><italic>si</italic></sub> represents the <italic>i</italic>th coordinate of the input vector. In addition, the level of the <italic>i</italic>th weight of neuron <italic>j</italic> is denoted by <italic>w</italic><sub><italic>ji</italic></sub>. The number of neurons in a Kohonen level is denoted by <italic>N</italic>&#x00D7;<italic>N</italic>. Once the winning neuron is selected, the corresponding weight <italic>w</italic><sub><italic>ji</italic></sub> of each neuron <italic>j</italic> in the layer is updated according to the difference between the original weight and the input neuron, as follows:</p>
<disp-formula id="S2.E2">
<label>(2)</label>
<mml:math id="M2">
<mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">&#x0394;</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mi mathvariant="normal">&#x03B7;</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo>(</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>-</mml:mo>
<mml:mfrac>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>max</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
<mml:mo>)</mml:mo>
</mml:mrow>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:msubsup>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>l</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo rspace="12.5pt">,</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>0</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>max</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>where the learning rate is &#x03B7;, the weight of the previous generation of <italic>w</italic><sub><italic>ji</italic></sub> is <inline-formula><mml:math id="INEQ2"><mml:msubsup><mml:mi>w</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2062;</mml:mo><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mo>&#x2062;</mml:mo><mml:mi>l</mml:mi><mml:mo>&#x2062;</mml:mo><mml:mi>d</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, and the number of neurons between neuron <italic>j</italic> and the superior neuron is represented by the topological distance <italic>d</italic><sub><italic>r</italic></sub>. The size of the adjacent area <italic>d</italic><sub><italic>max</italic></sub> decreases from the coverage of the entire network to the winning neurons as training progresses. In addition, the learning rate &#x03B7; changes during training:</p>
<disp-formula id="S2.E3">
<label>(3)</label>
<mml:math id="M3">
<mml:mrow>
<mml:mi mathvariant="normal">&#x03B7;</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msup>
<mml:mi mathvariant="normal">&#x03B7;</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msup>
<mml:mo>-</mml:mo>
<mml:msup>
<mml:mi mathvariant="normal">&#x03B7;</mml:mi>
<mml:mrow>
<mml:mi>f</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msup>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo>(</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>-</mml:mo>
<mml:mfrac>
<mml:msub>
<mml:mi>n</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>p</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>c</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mi>n</mml:mi>
<mml:mrow>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mfrac>
</mml:mrow>
<mml:mo>)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo>+</mml:mo>
<mml:msup>
<mml:mi mathvariant="normal">&#x03B7;</mml:mi>
<mml:mrow>
<mml:mi>f</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msup>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>where <italic>n</italic><sub><italic>tot</italic></sub> represents the total number of iterations; <italic>n</italic><sub><italic>epoch</italic></sub> represents the current iteration times.</p>
</sec>
<sec id="S3">
<title>3. SOS algorithm</title>
<p>In nature, some organisms establish symbiotic relationship, which strengthens their ability to adapt to the environment, thereby enhancing their viability. The SOS algorithm (<xref ref-type="bibr" rid="B5">Cheng and Prayogo, 2014</xref>) simulates the symbiotic relationships found in nature. Each organism in the ecosystem passes through three phases in the SOS algorithm: mutualism, commensalism, and parasitism. In each phase, the organism is assumed to be in a symbiotic relationship with another random organism. The interactions between the pairs of organisms are used to adjust the fitness value. The result is an optimal solution to the problem. The process is described in the following sections.</p>
<sec id="S3.SS1">
<title>3.1. Mutualist phase</title>
<p>In nature, the symbiosis between bees and flowers provides a mutual benefit, as both organisms can benefit. The formulae for updating organisms in mutually beneficial symbiosis are as follows:</p>
<disp-formula id="S3.E4">
<label>(4)</label>
<mml:math id="M4">
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>w</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>d</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mn>0</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo>&#x00D7;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>s</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>l</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi mathvariant="normal">_</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>c</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mrow>
<mml:mo>&#x00D7;</mml:mo>
<mml:mi>B</mml:mi>
</mml:mrow>
<mml:mo>&#x2062;</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="S3.E5">
<label>(5)</label>
<mml:math id="M5">
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>w</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>d</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mn>0</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo>&#x00D7;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>s</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>l</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi mathvariant="normal">_</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>c</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mrow>
<mml:mo>&#x00D7;</mml:mo>
<mml:mi>B</mml:mi>
</mml:mrow>
<mml:mo>&#x2062;</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="S3.E6">
<label>(6)</label>
<mml:math id="M6">
<mml:mrow>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>u</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>l</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi mathvariant="normal">_</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>c</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>o</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mrow>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:mfrac>
</mml:mrow>
</mml:math>
</disp-formula>
<p>where <italic>X</italic><sub><italic>i</italic></sub> and <italic>X</italic><sub><italic>j</italic></sub> represent two of the organisms in the ecosystem. <italic>X</italic><sub><italic>best</italic></sub> represent the best organism; <italic>Mutual</italic>_<italic>Vector</italic> represents the relationship between two organisms. The benefit factors are <italic>BF</italic><sub>1</sub> and <italic>BF</italic><sub>2</sub>, which have a value of 0 or 1. The unequal benefits obtained by the two parties from the symbiotic relationship are controlled by the benefit factors.</p>
</sec>
<sec id="S3.SS2">
<title>3.2. Commensal phase</title>
<p>An example of commensalism in nature is that between a remora and a shark. The remora benefits while the shark is neither harmed nor benefits. This symbiotic relationship is called partiality. The formula for the commensalism phase is</p>
<disp-formula id="S3.E7">
<label>(7)</label>
<mml:math id="M7">
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>w</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>d</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mo>-</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo>&#x00D7;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>e</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>s</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>where <italic>X</italic><sub><italic>i</italic></sub> is the party that makes a unilateral gain and <italic>X</italic><sub><italic>j</italic></sub> is the party that is not harmed.</p>
</sec>
<sec id="S3.SS3">
<title>3.3. Parasitic phase</title>
<p>In nature, parasitism occurs between mosquitoes and humans. The mosquitoes benefit, whereas the humans are hurt. In this stage, some of the dimensions of <italic>X</italic><sub><italic>i</italic></sub> are randomly selected and replaced by random values within the search space to form the artificial parasite<italic>Parasite</italic>_<italic>Vector</italic>. In the population randomly selected, we compare the fitness of an individual<italic>X</italic><sub><italic>j</italic></sub>(<italic>j</italic>&#x2260;<italic>i</italic>) with <italic>Parasite</italic>_<italic>Vector</italic>, and keep the optimal organism as the new <italic>X</italic><sub><italic>j</italic></sub>.</p>
</sec>
</sec>
<sec id="S4">
<title>4. Proposed SOS-Kohonen algorithm for intrusion detection</title>
<p>The SOS algorithm is based on the natural phenomenon of symbiosis between various organisms. When a virus intrudes into a system, the relation between the system and the virus can be viewed as a symbiotic relationship between the virus data and the system data.</p>
<p>The initial weights of the Kohonen neural network are optimized with the SOS algorithm. The optimized Kohonen neural network can reduce the length of the error vector between the training sample and the weight vector. This process helps to avoid rigidity during training, which can improve the clustering ability of the Kohonen neural network. After SOS training, the Kohonen neural network identifies subclasses with similar input patterns. Each subclass is used to train a specific radial basis network, which results in a local adjustment of the weights of the radial basis network. This can reduce the training burden of the radial basis network and improve the classification of the sample. For a Kohonen neural network trained by a sample data set, only one neuron in the competing layer is activated. A radial basis network corresponding to the activated winning neurons is used as input. Currently, the only neuron in the output layer is the transient stability index.</p>
<p>The steps in SOS-Kohonen intrusion detection are as follows:</p>
<p><italic>Step 1</italic>. Initialize the training data set, the number of symbiotic species, and the number of iterations.</p>
<p><italic>Step 2</italic>. The initial weights <italic>w</italic> are adjusted according to the Euclidean distance between the sample vector and the initial weight in the mutualist phase, commensal phase, and parasitic phase of the SOS algorithm.</p>
<p><italic>Step 3</italic>. The Kohonen neural network is trained according to the initial weight <italic>w</italic> optimized by the SOS algorithm.</p>
<p><italic>Step 4</italic>. The distance between the competing layer neuron <italic>j</italic> and the input vector <italic>X</italic> is calculated:</p>
<disp-formula id="S4.E8">
<label>(8)</label>
<mml:math id="M8">
<mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mo>|</mml:mo>
<mml:mrow>
<mml:munderover>
<mml:mo largeop="true" movablelimits="false" symmetric="true">&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>m</mml:mi>
</mml:munderover>
<mml:msup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:msup>
</mml:mrow>
<mml:mo>|</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo rspace="12.5pt">,</mml:mo>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</disp-formula>
<p><italic>Step 5.</italic> If the minimum distance has been reached, the competing layer neuron <italic>X</italic>, which matches the sample vector <italic>C</italic>, is the output neuron of the optimal matching.</p>
<p><italic>Step 6</italic>. Adjust the node weight coefficients in node <italic>c</italic> and neighborhood vector <italic>x</italic>:</p>
<disp-formula id="S4.Ex1">
<label>(9)</label>
<mml:math id="M9">
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">{</mml:mo>
<mml:mi>t</mml:mi>
<mml:mo stretchy="false">|</mml:mo>
<mml:mi>f</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mi>n</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>m</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mi>p</mml:mi>
<mml:mi>o</mml:mi>
<mml:msub>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>p</mml:mi>
<mml:mi>o</mml:mi>
<mml:msub>
<mml:mi>s</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&lt;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mo stretchy="false">}</mml:mo>
</mml:mrow>
<mml:mo rspace="12.5pt">,</mml:mo>
<mml:mi>j</mml:mi>
<mml:mo>=</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="S4.E9">
<mml:math id="M10">
<mml:mrow>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:mrow>
<mml:mi mathvariant="normal">&#x03B7;</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>X</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>The positions of neurons <italic>c</italic> and <italic>t</italic> are denoted by <italic>pos</italic><sub><italic>c</italic></sub> and <italic>pos</italic><sub><italic>t</italic></sub>, respectively. The distance between the two neurons is calculated in terms of <italic>norm</italic>(). &#x03B7; and <italic>r</italic> represent the learning rate and the neighborhood radius, respectively. They decrease linearly as the number of iterations increases.</p>
<p><italic>Step 7.</italic> If the stopping condition is met stop, otherwise return to step 3.</p>
<p><italic>Step 8</italic>. Read another test data set.</p>
<p><italic>Step 9</italic>. Cluster the input test data set according to the trained weight <italic>W</italic>.</p>
<p><italic>Step 10</italic>. Output the classification result.</p>
<p>Pseudocode corresponding to the steps of SOS-Kohonen intrusion detection is given in <xref ref-type="table" rid="A1">Algorithm 1</xref>.</p>
<table-wrap position="float" id="A1">
<label>Algorithm 1</label>
<caption><p>SOS-Kohonen neural network for virus intrusion detection.</p></caption>
<table cellspacing="5" cellpadding="5" frame="hsides" rules="groups">
<tbody>
<tr>
<td valign="top" align="left"><monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;<bold>Initialize:</bold> Populate <italic>n</italic> organisms in the</monospace><break/>
<monospace>ecosystem with random values</monospace><break/>
<monospace><bold>Input:</bold> Training data set</monospace><break/>
<monospace>Calculate the initial weights <italic>w</italic> by</monospace><break/>
<monospace>summing the points and output nodes of</monospace><break/>
<monospace>the Kohonen neural network</monospace><break/>
<monospace>Calculate the fitness of each organism</monospace><break/>
<monospace>Identify the best organism (<italic>X</italic><sub><italic>best</italic></sub>) in the</monospace><break/>
<monospace>initial population</monospace><break/>
<monospace>Define a stopping criterion (either a</monospace><break/>
<monospace>fixed number of generations/iterations or</monospace><break/>
<monospace>accuracy)</monospace><break/>
<monospace><bold>while (<italic>t</italic> &#x003C; MaxGeneration</bold>)</monospace><break/>
<monospace>&#x00A0;&#x00A0;<bold>for</bold> <italic>i</italic> = 1 to <italic>n</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;<italic>Mutualist phase</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Choose organism <italic>j</italic> randomly other</monospace><break/>
<monospace>than organism <italic>i</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Determine the beneficial factor and</monospace><break/>
<monospace>mutual vector via Eqs. (6)</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Modify organisms <italic>X</italic><sub><italic>i</italic></sub> and <italic>X</italic><sub><italic>j</italic></sub> based on</monospace><break/>
<monospace>their mutual relationship via Eqs. (4)</monospace><break/>
<monospace>and (5)</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Calculate new weights</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Evaluate the fitness of the new</monospace><break/>
<monospace>solution</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Accept the new solution if the</monospace><break/>
<monospace>fitness is better</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;<italic>End of mutualist phase</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;<italic>Commensal phase</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Choose organism <italic>j</italic> randomly other</monospace><break/>
<monospace>than organism <italic>i</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Modify organism <italic>X</italic><sub><italic>i</italic></sub> with the assist</monospace><break/>
<monospace>of organism <italic>X</italic><sub><italic>j</italic></sub> via Eq. (7)</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Calculate new weights</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Evaluate the fitness of the new</monospace><break/>
<monospace>solution</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Accept the new solution if the</monospace><break/>
<monospace>fitness is better</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;<italic>End of commensal phase</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;<italic>Parasitic phase</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Choose organism <italic>j</italic> randomly other</monospace><break/>
<monospace>than organism <italic>i</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Create a parasite (<italic>Parasite_Vector</italic>)</monospace><break/>
<monospace>from organism <italic>X</italic><sub><italic>i</italic></sub></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Calculate the fitness of the new</monospace><break/>
<monospace>organism</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Kill organism <italic>j</italic> and replace it with</monospace><break/>
<monospace>the parasite if its fitness is lower than</monospace><break/>
<monospace>the parasite&#x2019;s fitness</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Calculate new weights</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Evaluate the fitness of the new</monospace><break/>
<monospace>solution</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;Accept the new solution if the</monospace><break/>
<monospace>fitness is better</monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;<italic>End of parasitism phase</italic></monospace><break/>
<monospace>&#x00A0;&#x00A0;&#x00A0;&#x00A0;Update the best organism</monospace><break/>
<monospace>&#x00A0;&#x00A0;<bold>end for</bold></monospace><break/>
<monospace>&#x00A0;&#x00A0;<italic>t</italic> = <italic>t</italic> + 1</monospace><break/>
<monospace><bold>end while</bold></monospace><break/>
<monospace>Calculate the weight of the network</monospace><break/>
<monospace>according to the individual training</monospace><break/>
<monospace>weights <italic>w</italic></monospace><break/>
<monospace>Read another test data set</monospace><break/>
<monospace>Cluster the input test data set based on</monospace><break/>
<monospace>the trained weights</monospace><break/>
<monospace><bold>Output:</bold> Classification result</monospace>
</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The detection processes of BA-Kohonen, CS-Kohonen, FPA-Kohonen, GWO-Kohonen, and PSO-Kohonen can be imitated by SOS-Kohonen.</p>
</sec>
<sec id="S5">
<title>5. Data preprocessing</title>
<p>In intrusion detection, the network data to be assessed have multiple attributes with inconsistent units of measurement. If such data are used directly for intrusion detection, the accuracy and speed will be reduced. Therefore, the input data are pretreated, that is, normalized. The specific preprocessing method is as follows:</p>
<p>(1) The data are standardized so that the mean of each attribute is 0 and the variance is 1. The attributes of the initial network data are denoted by <italic>x</italic><sub><italic>ij</italic></sub>, and <inline-formula><mml:math id="INEQ9"><mml:mover accent="true"><mml:msub><mml:mi>x</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x00AF;</mml:mo></mml:mover></mml:math></inline-formula> and <italic>S</italic><sub><italic>j</italic></sub> represent the mean and variance of the <italic>j</italic>th dimension, respectively. The attributes are standardized as follows:</p>
<disp-formula id="S5.E10">
<label>(10)</label>
<mml:math id="M11">
<mml:mrow>
<mml:mover accent="true">
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x00AF;</mml:mo>
</mml:mover>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mfrac>
<mml:mn>1</mml:mn>
<mml:mi>n</mml:mi>
</mml:mfrac>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:munderover>
<mml:mo largeop="true" movablelimits="false" symmetric="true">&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>n</mml:mi>
</mml:munderover>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="S5.E11">
<label>(11)</label>
<mml:math id="M12">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>=</mml:mo>
<mml:msqrt>
<mml:mrow>
<mml:mfrac>
<mml:mn>1</mml:mn>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>-</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2062;</mml:mo>
<mml:mrow>
<mml:munderover>
<mml:mo largeop="true" movablelimits="false" symmetric="true">&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>n</mml:mi>
</mml:munderover>
<mml:msup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:msup>
</mml:mrow>
</mml:mrow>
</mml:msqrt>
</mml:mrow>
</mml:math>
</disp-formula>
<p>The normalized formula for (10) is as follows:</p>
<disp-formula id="S5.E12">
<label>(12)</label>
<mml:math id="M13">
<mml:mrow>
<mml:mrow>
<mml:msubsup>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:mover accent="true">
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x00AF;</mml:mo>
</mml:mover>
</mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mfrac>
</mml:mrow>
<mml:mo rspace="12.5pt">,</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:mrow>
<mml:mo rspace="5.3pt">,</mml:mo>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>(2) Normalize formula (10) to the range [0, 1] is as follows:</p>
<disp-formula id="S5.E13">
<label>(13)</label>
<mml:math id="M14">
<mml:mrow>
<mml:mrow>
<mml:msubsup>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>-</mml:mo>
<mml:mrow>
<mml:mi>min</mml:mi>
<mml:mo>&#x2061;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>max</mml:mi>
<mml:mo>&#x2061;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo>-</mml:mo>
<mml:mrow>
<mml:mi>min</mml:mi>
<mml:mo>&#x2061;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:msub>
<mml:mi>x</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
<mml:mo rspace="12.5pt">,</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:mrow>
<mml:mo rspace="5.3pt">,</mml:mo>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x2026;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
</sec>
<sec id="S6">
<title>6. Simulation experiments and analysis of results</title>
<p>To verify the effectiveness of SOS-Kohonen in detecting network intrusion by a virus, we ran two sets of tests with the proposed algorithm. The first verified the accuracy of SOS-Kohonen in classifying five types of virus. The second verified the ability of SOS-Kohonen to detect viruses hidden in normal data. The results for SOS-Kohonen were compared with results for Kohonen neural networks combined with one of five commonly used swarm intelligence algorithms: BA, CS, FPA, GWO, and PSO. The relevant parameters for these algorithms were set as follows:</p>
<p>BA: As in Ref. (<xref ref-type="bibr" rid="B32">Xinshe, 2010</xref>), r<sup>0</sup> = 0.5,<italic>A</italic> = 0.5,&#x03B1; = 0.95,&#x03B3; = 0.05.</p>
<p>CS: As in Ref.(<xref ref-type="bibr" rid="B34">Yang and Deb, 2009</xref>), &#x03B2; = 1.5, &#x03C1;<sub>0</sub> = 1.5.</p>
<p>FPA: As in Ref. (<xref ref-type="bibr" rid="B33">Yang, 2012</xref>),&#x03C1; = 0.8.</p>
<p>GWO: As recommended in Ref. (<xref ref-type="bibr" rid="B22">Mirjalili et al., 2014</xref>), <inline-formula><mml:math id="INEQ14"><mml:mover accent="true"><mml:mi mathvariant="normal">&#x03B1;</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula> = 0 to 2.</p>
<p>PSO: Weight factor &#x03C9; = 0.6,<italic>c</italic><sub>1</sub> = <italic>c</italic><sub>2</sub> = 2(<xref ref-type="bibr" rid="B19">Kennedy and Eberhart, 1995</xref>), and population size is 15.</p>
<p>SOS: As in Ref. (<xref ref-type="bibr" rid="B5">Cheng and Prayogo, 2014</xref>), population size is 15.</p>
<sec id="S6.SS1">
<title>6.1. Experimental setup</title>
<p>The development environment for this test was MATLAB R2012a. The tests were run on an AMD Athlont (tm) II&#x002A;4640 processor with 4 GB of memory.</p>
</sec>
<sec id="S6.SS2">
<title>6.2. Simulation of virus classification by SOS-Kohonen</title>
<p>In this section, we tested the accuracy of SOS-Kohonen in virus classification. The standard network intrusion test data set contains five categories of virus data. We extracted 4000 training samples, as shown in <xref ref-type="table" rid="T1">Table 1</xref> and <xref ref-type="fig" rid="F2">Figure 2A</xref>. Each sample contained a 38-dimensional feature that is used to represent the different attributes of the network intrusion data. Attack type 5 had the fewest training samples and type 2 had the most.</p>
<table-wrap position="float" id="T1">
<label>TABLE 1</label>
<caption><p>Number of samples for each attack type.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Attack type</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Number of samples</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center">1,399</td>
</tr>
<tr>
<td valign="top" align="left">2</td>
<td valign="top" align="center">1,862</td>
</tr>
<tr>
<td valign="top" align="left">3</td>
<td valign="top" align="center">115</td>
</tr>
<tr>
<td valign="top" align="left">4</td>
<td valign="top" align="center">580</td>
</tr>
<tr>
<td valign="top" align="left">5</td>
<td valign="top" align="center">44</td>
</tr>
</tbody>
</table></table-wrap>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption><p>Percentages of each attack type for <bold>(A)</bold> training data set. <bold>(B)</bold> Four randomly selected cases.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fncom-17-1079483-g002.tif"/>
</fig>
<p>Four subsets were randomly selected from the virus intrusion detection data set as test cases. The percentages for the five attack types in the four cases varied (<xref ref-type="fig" rid="F2">Figure 2B</xref>). The number of samples in each case was different, as shown in <xref ref-type="table" rid="T3">Table 3</xref>.</p>
<table-wrap position="float" id="T2">
<label>TABLE 2</label>
<caption><p>Statistics for results for the four cases for each algorithm.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Case</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Result</td>
<td valign="top" align="center" colspan="6" style="color:#ffffff;background-color: #7f8080;">Method</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>BA-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>CS-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>FPA-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>GWO-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>PSO-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>SOS-Kohonen</bold></td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">1</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.033333</td>
<td valign="top" align="center">0.06</td>
<td valign="top" align="center">0.051111</td>
<td valign="top" align="center">0.04</td>
<td valign="top" align="center">0.046667</td>
<td valign="top" align="center">0.033333</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.537778</td>
<td valign="top" align="center">0.191111</td>
<td valign="top" align="center">0.2</td>
<td valign="top" align="center">0.602222</td>
<td valign="top" align="center">0.206667</td>
<td valign="top" align="center">0.064444</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.270444</td>
<td valign="top" align="center">0.100889</td>
<td valign="top" align="center">0.14</td>
<td valign="top" align="center">0.152667</td>
<td valign="top" align="center">0.117778</td>
<td valign="top" align="center">0.048889</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.177392</td>
<td valign="top" align="center">0.050231</td>
<td valign="top" align="center">0.065822</td>
<td valign="top" align="center">0.172365</td>
<td valign="top" align="center">0.072153</td>
<td valign="top" align="center">0.008446</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">2</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.033333</td>
<td valign="top" align="center">0.017647</td>
<td valign="top" align="center">0.019608</td>
<td valign="top" align="center">0.014379</td>
<td valign="top" align="center">0.01634</td>
<td valign="top" align="center">0.010458</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.219608</td>
<td valign="top" align="center">0.061438</td>
<td valign="top" align="center">0.066013</td>
<td valign="top" align="center">0.799346</td>
<td valign="top" align="center">0.066013</td>
<td valign="top" align="center">0.019608</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.153529</td>
<td valign="top" align="center">0.03085</td>
<td valign="top" align="center">0.045425</td>
<td valign="top" align="center">0.113725</td>
<td valign="top" align="center">0.038431</td>
<td valign="top" align="center">0.015229</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.071594</td>
<td valign="top" align="center">0.017234</td>
<td valign="top" align="center">0.021783</td>
<td valign="top" align="center">0.242131</td>
<td valign="top" align="center">0.022362</td>
<td valign="top" align="center">0.003173</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">3</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.011494</td>
<td valign="top" align="center">0.008812</td>
<td valign="top" align="center">0.010345</td>
<td valign="top" align="center">0.008812</td>
<td valign="top" align="center">0.008429</td>
<td valign="top" align="center">0.006897</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.401149</td>
<td valign="top" align="center">0.033333</td>
<td valign="top" align="center">0.038697</td>
<td valign="top" align="center">0.608046</td>
<td valign="top" align="center">0.038697</td>
<td valign="top" align="center">0.011494</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.242261</td>
<td valign="top" align="center">0.012912</td>
<td valign="top" align="center">0.02908</td>
<td valign="top" align="center">0.08636</td>
<td valign="top" align="center">0.028467</td>
<td valign="top" align="center">0.009464</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.182699</td>
<td valign="top" align="center">0.007303</td>
<td valign="top" align="center">0.012269</td>
<td valign="top" align="center">0.18368</td>
<td valign="top" align="center">0.012612</td>
<td valign="top" align="center">0.001666</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">4</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.026608</td>
<td valign="top" align="center">0.007895</td>
<td valign="top" align="center">0.008772</td>
<td valign="top" align="center">0.004386</td>
<td valign="top" align="center">0.006433</td>
<td valign="top" align="center">0.005556</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.48655</td>
<td valign="top" align="center">0.029532</td>
<td valign="top" align="center">0.029532</td>
<td valign="top" align="center">0.484795</td>
<td valign="top" align="center">0.029532</td>
<td valign="top" align="center">0.008772</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.161374</td>
<td valign="top" align="center">0.015</td>
<td valign="top" align="center">0.024415</td>
<td valign="top" align="center">0.057018</td>
<td valign="top" align="center">0.015058</td>
<td valign="top" align="center">0.007661</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.214127</td>
<td valign="top" align="center">0.009504</td>
<td valign="top" align="center">0.008512</td>
<td valign="top" align="center">0.150482</td>
<td valign="top" align="center">0.009798</td>
<td valign="top" align="center">0.001101</td>
</tr>
</tbody>
</table></table-wrap>
<table-wrap position="float" id="T3">
<label>TABLE 3</label>
<caption><p>Comparison of detection rates for the six algorithms.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Case</td>
<td valign="top" align="center" colspan="5" style="color:#ffffff;background-color: #7f8080;">Attack type</td>
<td valign="top" align="center" colspan="6" style="color:#ffffff;background-color: #7f8080;">Detection rate</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>1</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>2</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>3</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>4</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>5</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>BA</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>CS</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>FPA</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>GWO</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>PSO</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>SOS</bold></td>
</tr>
<tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center">149</td>
<td valign="top" align="center">208</td>
<td valign="top" align="center">14</td>
<td valign="top" align="center">71</td>
<td valign="top" align="center">8</td>
<td valign="top" align="center">97.84%</td>
<td valign="top" align="center">97.78%</td>
<td valign="top" align="center">97.62%</td>
<td valign="top" align="center">97.73%</td>
<td valign="top" align="center">96.36%</td>
<td valign="top" align="center">98.53%</td>
</tr>
<tr>
<td valign="top" align="left">2</td>
<td valign="top" align="center">1094</td>
<td valign="top" align="center">235</td>
<td valign="top" align="center">95</td>
<td valign="top" align="center">78</td>
<td valign="top" align="center">28</td>
<td valign="top" align="center">99.07%</td>
<td valign="top" align="center">99.29%</td>
<td valign="top" align="center">99.04%</td>
<td valign="top" align="center">98.93%</td>
<td valign="top" align="center">99%</td>
<td valign="top" align="center">99.54%</td>
</tr>
<tr>
<td valign="top" align="left">3</td>
<td valign="top" align="center">1263</td>
<td valign="top" align="center">914</td>
<td valign="top" align="center">17</td>
<td valign="top" align="center">108</td>
<td valign="top" align="center">308</td>
<td valign="top" align="center">87.57%</td>
<td valign="top" align="center">99.08%</td>
<td valign="top" align="center">99.56%</td>
<td valign="top" align="center">99.43%</td>
<td valign="top" align="center">99.61%</td>
<td valign="top" align="center">99.73%</td>
</tr>
<tr>
<td valign="top" align="left">4</td>
<td valign="top" align="center">1146</td>
<td valign="top" align="center">1556</td>
<td valign="top" align="center">212</td>
<td valign="top" align="center">81</td>
<td valign="top" align="center">425</td>
<td valign="top" align="center">99.63%</td>
<td valign="top" align="center">99.66%</td>
<td valign="top" align="center">99.63%</td>
<td valign="top" align="center">99.74%</td>
<td valign="top" align="center">99.69%</td>
<td valign="top" align="center">99.78%</td>
</tr>
<tr>
<td valign="top" align="left" colspan="6">Average detection rate</td>
<td valign="top" align="center">96.03%</td>
<td valign="top" align="center">98.95%</td>
<td valign="top" align="center">98.96%</td>
<td valign="top" align="center">98.96%</td>
<td valign="top" align="center">98.66%</td>
<td valign="top" align="center">99.4%</td>
</tr>
</tbody>
</table></table-wrap>
<p>For each case, we conducted 10 independent tests using each of the six group intelligence algorithms to determine the weights for the Kohonen neural network. It can be seen that the SOS-Kohonen algorithm has a preference better than BA-Kohonen, CS-Kohonen, FPA-Kohonen, GWO-Kohonen, or PSO-Kohonen, both in terms of optimal value and variance for the accuracy. It also had stronger robustness.</p>
<p><xref ref-type="fig" rid="F3">Figures 3C, G, K, O</xref> show the expected classification results for cases 1 to 4. <xref ref-type="fig" rid="F3">Figures 3D, H, L, P</xref> show the actual results for these cases for SOS-Kohonen. Due to space constraints, we show the results only for the highest detection rate from the 10 independent runs. The detection rate is defined in Section &#x201C;6.3. Simulation of virus detection by SOS-Kohonen.&#x201D; The red circles indicate differences between the actual detection and the expected detection. <xref ref-type="fig" rid="F3">Figures 3D, L, P</xref> have only one error, whereas <xref ref-type="fig" rid="F3">Figure 3H</xref> has five.</p>
<fig id="F3" position="float">
<label>FIGURE 3</label>
<caption><p>Cases 1- 4 expected classification results are <bold>(C,G,K,O)</bold>; actual classification results are <bold>(D,H,L,P)</bold>; fitness evolution curves are <bold>(E,I,M,R)</bold>; ANOVA test of optimal paths are <bold>(F,J,N,S)</bold>; respectively.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fncom-17-1079483-g003.tif"/>
</fig>
<p><xref ref-type="table" rid="T3">Table 3</xref> lists the detection rates for the six algorithms for the four cases. SOS-Kohonen had higher detection rates than the BA-Kohonen, CS-Kohonen, FPA-Kohonen, GWO-Kohonen, or PSO-Kohonen algorithms. It achieved an average detection rate of 99.4% in classifying intrusion data.</p>
<p><xref ref-type="fig" rid="F3">Figures 3E, I, M, R</xref> illustrate the convergence of the six algorithms. It can be seen that SOS converged fastest and with the highest accuracy. <xref ref-type="fig" rid="F3">Figures 3F, J, N, S</xref> are variance maps for each algorithm. The SOS algorithm had the strongest stability and highest robustness compared to the other algorithms.</p>
</sec>
<sec id="S6.SS3">
<title>6.3. Simulation of virus detection by SOS-Kohonen</title>
<p>This section uses the internationally accepted KDDCUP99 (<xref ref-type="bibr" rid="B18">KDD Cup 1999 Data, 1999</xref>; <xref ref-type="bibr" rid="B23">MIT Lincoln Laboratory, 2009</xref>; <xref ref-type="bibr" rid="B2">Aggarwal and Sharma, 2015</xref>) data set to verify the detection performance of SOS-Kohonen. The KDDCUP99 data set was established by the Lincoln Laboratory of the Massachusetts Institute of Technology. The data set was collected using tcpdump from a simulated network environment over 9 weeks. This database has become a benchmark for network intrusion detection and can be used in comprehensive tests of the performance of intrusion detection algorithms. Attacks in the data set include denial of service attacks (DOS), scan attacks (probe), remote user unauthorized access attacks (U2L), and unauthorized use of local super-privilege access attacks (U2R). We apply the internationally accepted detection rate and false alarm rate as evaluation indicators, which are defined as follows (<xref ref-type="bibr" rid="B11">Ganapathy et al., 2012</xref>; <xref ref-type="bibr" rid="B20">Lin et al., 2015</xref>):</p>
<disp-formula id="S6.E14">
<label>(14)</label>
<mml:math id="M15">
<mml:mrow>
<mml:mrow>
<mml:mpadded width="+2.8pt">
<mml:mi>Detection</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>rate</mml:mi>
</mml:mrow>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mfrac>
<mml:mrow>
<mml:mpadded width="+2.8pt">
<mml:mi>Number</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>of</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>attack</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>samples</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>found</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mpadded width="+2.8pt">
<mml:mi>Total</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>number</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>of</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>attacks</mml:mi>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x00D7;</mml:mo>
<mml:mrow>
<mml:mn>100</mml:mn>
<mml:mo>%</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="S6.E15">
<label>(15)</label>
<mml:math id="M16">
<mml:mrow>
<mml:mrow>
<mml:mpadded width="+2.8pt">
<mml:mi>False</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>alarm</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>rate</mml:mi>
</mml:mrow>
<mml:mo>=</mml:mo>
<mml:mrow>
<mml:mfrac>
<mml:mtable rowspacing="0pt">
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mrow>
<mml:mpadded width="+2.8pt">
<mml:mi>Number</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>of</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>correct</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>samples</mml:mi>
</mml:mrow>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mrow>
<mml:mpadded lspace="20pt" width="+22.8pt">
<mml:mi>that</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>were</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>misjudged</mml:mi>
</mml:mrow>
</mml:mtd>
</mml:mtr>
</mml:mtable>
<mml:mrow>
<mml:mpadded width="+2.8pt">
<mml:mi>Total</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>number</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>of</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mpadded width="+2.8pt">
<mml:mi>correct</mml:mi>
</mml:mpadded>
<mml:mo>&#x2062;</mml:mo>
<mml:mi>samples</mml:mi>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x00D7;</mml:mo>
<mml:mrow>
<mml:mn>100</mml:mn>
<mml:mo>%</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<p>We randomly selected 6,000 samples as training data, including normal data and the four kinds of intrusion data. The percentages of these five types of data are given in <xref ref-type="fig" rid="F6">Figure 4</xref>. Among them, normal samples were the most common and U2R samples the least common. We then randomly selected four subsets from the KDDCUP99 data set as test cases. The number of each attack type for each case are plotted in <xref ref-type="fig" rid="F7">Figure 5</xref> and listed in <xref ref-type="table" rid="T4">Table 4</xref>.</p>
<fig id="F6" position="float">
<label>FIGURE 4</label>
<caption><p>Percentage of each attack type in the training data set.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fncom-17-1079483-g004.tif"/>
</fig>
<fig id="F7" position="float">
<label>FIGURE 5</label>
<caption><p>Specific proportions of the test data.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fncom-17-1079483-g005.tif"/>
</fig>
<table-wrap position="float" id="T4">
<label>TABLE 4</label>
<caption><p>Number of samples for each test case for each attack type.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Case</td>
<td valign="top" align="center" colspan="5" style="color:#ffffff;background-color: #7f8080;">Attack type</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>Normal</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>DOS</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>U2L</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>U2R</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>Probe</bold></td>
</tr>
<tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center">308</td>
<td valign="top" align="center">78</td>
<td valign="top" align="center">178</td>
<td valign="top" align="center">3</td>
<td valign="top" align="center">33</td>
</tr>
<tr>
<td valign="top" align="left">2</td>
<td valign="top" align="center">1007</td>
<td valign="top" align="center">290</td>
<td valign="top" align="center">636</td>
<td valign="top" align="center">10</td>
<td valign="top" align="center">157</td>
</tr>
<tr>
<td valign="top" align="left">3</td>
<td valign="top" align="center">1558</td>
<td valign="top" align="center">409</td>
<td valign="top" align="center">913</td>
<td valign="top" align="center">15</td>
<td valign="top" align="center">225</td>
</tr>
<tr>
<td valign="top" align="left">4</td>
<td valign="top" align="center">2078</td>
<td valign="top" align="center">529</td>
<td valign="top" align="center">1024</td>
<td valign="top" align="center">21</td>
<td valign="top" align="center">308</td>
</tr>
</tbody>
</table></table-wrap>
<p>In this paper, 10 independent experiments were carried out for each algorithm for the four cases. As can be seen from <xref ref-type="table" rid="T5">Table 5</xref>, for cases 1, 2, and 3, the SOS-Kohonen algorithm has higher search accuracy than the other algorithms. In case 4, although the optimal value for SOS is slightly worse than that for GWO, the average of the 10 runs was still better than that of the other five algorithms. This shows that the SOS-Kohonen algorithm has a strong search ability and robustness as a whole.</p>
<table-wrap position="float" id="T5">
<label>TABLE 5</label>
<caption><p>Statistics for accuracy for the four cases for each algorithm.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Case</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Result</td>
<td valign="top" align="center" colspan="6" style="color:#ffffff;background-color: #7f8080;">Method</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>BA-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>CS-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>FPA-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>GWO-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>PSO-Kohonen</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>SOS-Kohonen</bold></td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">1</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.106667</td>
<td valign="top" align="center">0.2</td>
<td valign="top" align="center">0.198333</td>
<td valign="top" align="center">0.095</td>
<td valign="top" align="center">0.151667</td>
<td valign="top" align="center">0.09</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.488333</td>
<td valign="top" align="center">0.331667</td>
<td valign="top" align="center">0.375</td>
<td valign="top" align="center">0.361667</td>
<td valign="top" align="center">0.365</td>
<td valign="top" align="center">0.236667</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.3475</td>
<td valign="top" align="center">0.282833</td>
<td valign="top" align="center">0.2965</td>
<td valign="top" align="center">0.201667</td>
<td valign="top" align="center">0.284</td>
<td valign="top" align="center">0.156333</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.11302</td>
<td valign="top" align="center">0.037392</td>
<td valign="top" align="center">0.056675</td>
<td valign="top" align="center">0.102524</td>
<td valign="top" align="center">0.071868</td>
<td valign="top" align="center">0.065106</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">2</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.258095</td>
<td valign="top" align="center">0.239048</td>
<td valign="top" align="center">0.273333</td>
<td valign="top" align="center">0.161429</td>
<td valign="top" align="center">0.142857</td>
<td valign="top" align="center">0.082857</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.560476</td>
<td valign="top" align="center">0.36381</td>
<td valign="top" align="center">0.397619</td>
<td valign="top" align="center">0.690952</td>
<td valign="top" align="center">0.394762</td>
<td valign="top" align="center">0.252857</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.391762</td>
<td valign="top" align="center">0.306048</td>
<td valign="top" align="center">0.319762</td>
<td valign="top" align="center">0.329905</td>
<td valign="top" align="center">0.274238</td>
<td valign="top" align="center">0.166524</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.085917</td>
<td valign="top" align="center">0.046231</td>
<td valign="top" align="center">0.034559</td>
<td valign="top" align="center">0.177668</td>
<td valign="top" align="center">0.081504</td>
<td valign="top" align="center">0.054313</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="4">3</td>
<td valign="top" align="center">Best</td>
<td valign="top" align="center">0.251923</td>
<td valign="top" align="center">0.107692</td>
<td valign="top" align="center">0.298397</td>
<td valign="top" align="center">0.150321</td>
<td valign="top" align="center">0.185897</td>
<td valign="top" align="center">0.11859</td>
</tr>
<tr>
<td valign="top" align="center">Worst</td>
<td valign="top" align="center">0.482372</td>
<td valign="top" align="center">0.379487</td>
<td valign="top" align="center">0.384295</td>
<td valign="top" align="center">0.365705</td>
<td valign="top" align="center">0.380128</td>
<td valign="top" align="center">0.294231</td>
</tr>
<tr>
<td valign="top" align="center">Mean</td>
<td valign="top" align="center">0.361699</td>
<td valign="top" align="center">0.273526</td>
<td valign="top" align="center">0.356571</td>
<td valign="top" align="center">0.257981</td>
<td valign="top" align="center">0.320897</td>
<td valign="top" align="center">0.187404</td>
</tr>
<tr>
<td valign="top" align="center">Std</td>
<td valign="top" align="center">0.082383</td>
<td valign="top" align="center">0.081583</td>
<td valign="top" align="center">0.025715</td>
<td valign="top" align="center">0.085018</td>
<td valign="top" align="center">0.065687</td>
<td valign="top" align="center">0.052848</td>
</tr>
<tr>
<td valign="top" align="left">4</td>
<td valign="top" align="center">Best<break/> Worst<break/> Mean<break/> Std</td>
<td valign="top" align="center">0.253382<break/> 0.497826<break/> 0.389348<break/> 0.091809</td>
<td valign="top" align="center">0.173913<break/> 0.339855<break/> 0.27657<break/> 0.050181</td>
<td valign="top" align="center">0.251691<break/> 0.394444<break/> 0.319324<break/> 0.049568</td>
<td valign="top" align="center">0.089372<break/> 0.378986<break/> 0.232729<break/> 0.106131</td>
<td valign="top" align="center">0.189614<break/> 0.419082<break/> 0.326715<break/> 0.067197</td>
<td valign="top" align="center">0.104106<break/> 0.301449<break/> 0.2143<break/> 0.059002</td>
</tr>
</tbody>
</table></table-wrap>
<p><xref ref-type="fig" rid="F9">Figures 6C1, G1, K1, O1</xref> show the expected test results for cases 1 to 4, and <xref ref-type="fig" rid="F9">Figures 6D1, H1, L1, P1</xref> show the actual test results for SOS-Kohonen. Due to space constraints, we show the results only for the highest detection rate from the 10 independent runs. The normal data are represented as blue dots, and the other colors represent the four types of intrusion data. The red circles indicate differences between the actual detection and the expected detection.</p>
<fig id="F9" position="float">
<label>FIGURE 6</label>
<caption><p>Cases 1&#x2013;4 expected classification results are <bold>(C<sub><bold>1</bold></sub>,G<sub><bold>1</bold></sub>,K<sub><bold>1</bold></sub>,O<sub><bold>1</bold></sub>)</bold>; actual classification results are <bold>(D<sub><bold>1</bold></sub>,H<sub><bold>1</bold></sub>,L<sub><bold>1</bold></sub>,P<sub><bold>1</bold></sub>)</bold>; fitness evolution curves are <bold>(E<sub><bold>1</bold></sub>,I<sub><bold>1</bold></sub>,M<sub><bold>1</bold></sub>,R<sub><bold>1</bold></sub>)</bold>; ANOVA test of optimal paths are <bold>(F<sub><bold>1</bold></sub>,J<sub><bold>1</bold></sub>,N<sub><bold>1</bold></sub>,S<sub><bold>1</bold></sub>)</bold>; respectively.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fncom-17-1079483-g006.tif"/>
</fig>
<p><xref ref-type="table" rid="T6">Table 6</xref> shows the average detection rates and average false alarm rates for the six algorithms for the four cases. It can be seen that SOS-Kohonen had a higher detection rate and lower false alarm rate than BA-Kohonen, CS-Kohonen, FPA-Kohonen, GWO-Kohonen, or PSO-Kohonen. The average detection rate of SOS-Kohonen was 94.51%.</p>
<table-wrap position="float" id="T6">
<label>TABLE 6</label>
<caption><p>Comparison of average detection rate and average false alarm rate for the six algorithms.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Case</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Result</td>
<td valign="top" align="center" colspan="6" style="color:#ffffff;background-color: #7f8080;">Method</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>BA</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>CS</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>FPA</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>GWO</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>PSO</bold></td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;"><bold>SOS</bold></td>
</tr>
<tr>
<td valign="top" align="left" rowspan="2">1</td>
<td valign="top" align="center">Detection rate</td>
<td valign="top" align="center">85.24%</td>
<td valign="top" align="center">89.69%</td>
<td valign="top" align="center">90.75%</td>
<td valign="top" align="center">88.56%</td>
<td valign="top" align="center">90.55%</td>
<td valign="top" align="center">95.45%</td>
</tr>
<tr>
<td valign="top" align="center">False alarm rate</td>
<td valign="top" align="center">10.33%</td>
<td valign="top" align="center">7.98%</td>
<td valign="top" align="center">7.25%</td>
<td valign="top" align="center">7.97%</td>
<td valign="top" align="center">7.47%</td>
<td valign="top" align="center">5.20%</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="2">2</td>
<td valign="top" align="center">Detection rate</td>
<td valign="top" align="center">84.38%</td>
<td valign="top" align="center">90.65%</td>
<td valign="top" align="center">87.58%</td>
<td valign="top" align="center">87.56%</td>
<td valign="top" align="center">84.76%</td>
<td valign="top" align="center">96.26%</td>
</tr>
<tr>
<td valign="top" align="center">False alarm rate</td>
<td valign="top" align="center">12.34%</td>
<td valign="top" align="center">7.94%</td>
<td valign="top" align="center">9.91%</td>
<td valign="top" align="center">8.76%</td>
<td valign="top" align="center">11.25%</td>
<td valign="top" align="center">4.67%</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="2">3</td>
<td valign="top" align="center">Detection rate</td>
<td valign="top" align="center">91.59%</td>
<td valign="top" align="center">90.13%</td>
<td valign="top" align="center">83.69%</td>
<td valign="top" align="center">89.28%</td>
<td valign="top" align="center">80.54%</td>
<td valign="top" align="center">94.90%</td>
</tr>
<tr>
<td valign="top" align="center">False alarm rate</td>
<td valign="top" align="center">8.11%</td>
<td valign="top" align="center">7.47%</td>
<td valign="top" align="center">10.82%</td>
<td valign="top" align="center">8.32%</td>
<td valign="top" align="center">12.17%</td>
<td valign="top" align="center">5.44%</td>
</tr>
<tr>
<td valign="top" align="left" rowspan="2">4</td>
<td valign="top" align="center">Detection rate</td>
<td valign="top" align="center">85.42%</td>
<td valign="top" align="center">86.14%</td>
<td valign="top" align="center">80.45%</td>
<td valign="top" align="center">84.19%</td>
<td valign="top" align="center">90.39%</td>
<td valign="top" align="center">91.43%</td>
</tr>
<tr>
<td valign="top" align="center">False alarm rate</td>
<td valign="top" align="center">9.43%</td>
<td valign="top" align="center">10.50%</td>
<td valign="top" align="center">11.77%</td>
<td valign="top" align="center">11.69%</td>
<td valign="top" align="center">7.07%</td>
<td valign="top" align="center">6.79%</td>
</tr>
<tr>
<td valign="top" align="left" colspan="2">Average detection rate</td>
<td valign="top" align="center">86.66%</td>
<td valign="top" align="center">89.16%</td>
<td valign="top" align="center">85.62%</td>
<td valign="top" align="center">87.40%</td>
<td valign="top" align="center">86.56%</td>
<td valign="top" align="center">94.51%</td>
</tr>
</tbody>
</table></table-wrap>
<p><xref ref-type="fig" rid="F9">Figures 6E1, I1, M1, R1</xref> show the convergence of the six algorithms. The convergence speed and accuracy of SOS-Kohonen were better than those of the other algorithms. <xref ref-type="fig" rid="F9">Figures 6F1, J1, N1, S1</xref> show the variance of each algorithm. For each case, the SOS-Kohonen algorithm had the second best variance ranked second but the highest search accuracy. Overall, the SOS-Kohonen algorithm performed better than the other algorithms.</p>
</sec>
<sec id="S6.SS4">
<title>6.4. <italic>p</italic>-values from the Wilcoxon rank-sum test</title>
<p>Next, we ran the Wilcoxon rank-sum test (<xref ref-type="bibr" rid="B7">Derrac et al., 2011</xref>; <xref ref-type="bibr" rid="B12">Gibbons and Chakraborti, 2011</xref>; <xref ref-type="bibr" rid="B13">Hollander et al., 2013</xref>) for SOS-Kohonen and the other five algorithms. We chose <italic>p</italic> = 0.05 as the level of significance. <xref ref-type="table" rid="T7">Table 7</xref> shows the <italic>p</italic>-values for the four classification cases described in Section &#x201C;6.2. Simulation of virus classification by SOS-Kohonen.&#x201D; <xref ref-type="table" rid="T8">Table 8</xref> shows the <italic>p</italic>-values for the four detection cases described in Section &#x201C;6.3. Simulation of virus detection by SOS-Kohonen&#x201D;</p>
<table-wrap position="float" id="T7">
<label>TABLE 7</label>
<caption><p><italic>p</italic>-values from the Wilcoxon rank-sum test for the four classification cases.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Algorithm</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 1</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 2</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 3</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 4</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">SOS vs. BA</td>
<td valign="top" align="center">0.0079</td>
<td valign="top" align="center">1.7462 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">2.3697 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">1.6589 &#x00D7; 10<sup>&#x2013;4</sup></td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. CS</td>
<td valign="top" align="center">4.7751 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">0.0021</td>
<td valign="top" align="center">0.0608</td>
<td valign="top" align="center">0.0051</td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. FPA</td>
<td valign="top" align="center">4.8226 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">3.8732 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">7.2031 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">2.5197 &#x00D7; 10<sup>&#x2013;4</sup></td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. GWO</td>
<td valign="top" align="center">0.0404</td>
<td valign="top" align="center">0.0441</td>
<td valign="top" align="center">0.0012</td>
<td valign="top" align="center">0.9696</td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. PSO</td>
<td valign="top" align="center">0.0062</td>
<td valign="top" align="center">0.0013</td>
<td valign="top" align="center">0.0023</td>
<td valign="top" align="center">0.1267</td>
</tr>
</tbody>
</table></table-wrap>
<table-wrap position="float" id="T8">
<label>TABLE 8</label>
<caption><p><italic>p</italic>-values from the Wilcoxon rank-sum test for the four detection cases.</p></caption>
<table cellspacing="5" cellpadding="5" frame="box" rules="all">
<thead>
<tr>
<td valign="top" align="left" style="color:#ffffff;background-color: #7f8080;">Algorithm</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 1</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 2</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 3</td>
<td valign="top" align="center" style="color:#ffffff;background-color: #7f8080;">Case 4</td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">SOS vs. BA</td>
<td valign="top" align="center">0.0022</td>
<td valign="top" align="center">1.8165 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">4.3745 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">7.6502 &#x00D7; 10<sup>&#x2013;4</sup></td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. CS</td>
<td valign="top" align="center">4.3964 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">3.2643 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">0.0172</td>
<td valign="top" align="center">0.0312</td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. FPA</td>
<td valign="top" align="center">5.8006 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">1.8063 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">1.8165 &#x00D7; 10<sup>&#x2013;4</sup></td>
<td valign="top" align="center">0.0017</td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. GWO</td>
<td valign="top" align="center">0.5452</td>
<td valign="top" align="center">0.0058</td>
<td valign="top" align="center">0.0639</td>
<td valign="top" align="center">0.6232</td>
</tr>
<tr>
<td valign="top" align="left">SOS vs. PSO</td>
<td valign="top" align="center">0.0028</td>
<td valign="top" align="center">0.0073</td>
<td valign="top" align="center">0.0010</td>
<td valign="top" align="center">0.0036</td>
</tr>
</tbody>
</table></table-wrap>
<p>In <xref ref-type="table" rid="T7">Table 7</xref>, for case 3, the <italic>p</italic>-value for SOS vs CS is greater than 0.05. For case 4, the <italic>p</italic>-values for SOS vs GWO and SOS vs PSO are greater than 0.05. All other <italic>p</italic>-values are less than 0.05. In <xref ref-type="table" rid="T8">Table 8</xref>, the only <italic>p</italic>-values greater than 0.05 are for SOS vs GWO for cases 1, 3, and 4. Thus, for most of the eight tests cases, the differences between SOS and the other algorithms were statistically significant and not due to chance.</p>
</sec>
<sec id="S6.SS5">
<title>6.5. Analysis of results</title>
<p>In this paper, six common swarm intelligence algorithms were combined with Kohonen neural network and used to simulate the intrusion detection of network viruses. We ran two sets of tests. In Section &#x201C;6.2. Simulation of virus classification by SOS-Kohonen,&#x201D; we tested the classification accuracy of the algorithms. <xref ref-type="fig" rid="F3">Figures 3C&#x2014;S</xref> show the classification results, convergence, and variance maps for the four test cases. <xref ref-type="table" rid="T2">Table 2</xref> lists the classification accuracy of the six swarm intelligence algorithms.</p>
<p>In Section &#x201C;6.3. Simulation of virus detection by SOS-Kohonen,&#x201D; we assessed the detection rate and false alarm rate for normal data and four attack types. <xref ref-type="fig" rid="F9">Figures 6C1&#x2014;S1</xref> show the classification results, convergence, and variance maps for the four test cases. <xref ref-type="table" rid="T6">Table 6</xref> compares the average detection rates and false alarm rates for the six algorithms.</p>
<p>In Section &#x201C;6.4. <italic>p</italic>-values from the Wilcoxon rank-sum test,&#x201D; we ran the Wilcoxon rank-sum test. For most of the eight tests cases, the differences between SOS and the other algorithms were statistically significant and not due to chance. Thus, the SOS-Kohonen algorithm is more effective than the other five swarm intelligence algorithms in detecting network intrusion by a virus.</p>
</sec>
</sec>
<sec id="S7" sec-type="conclusions">
<title>7. Conclusions and future work</title>
<p>With the continuous development and popularization of the Internet, there is much more convenient access to network resources. However, this has led to a continuous increase in security problems due to virus intrusion. In this paper, we combined a swarm intelligence algorithm with a neural network to detect network intrusion by a virus. Our approach is described in detail, and it was tested with the international KDDCUP99 intrusion data set, which verified its effectiveness. Moreover, this is also a new method for detecting network intrusion by a virus. With the rapid development of cloud computing and big data, our future work will consider the application of SOS- Kohonen to heterogeneous distributed systems.</p>
</sec>
<sec id="S8" sec-type="data-availability">
<title>Data availability statement</title>
<p>The original contributions presented in this study are included in the article/supplementary material, further inquiries can be directed to the corresponding authors.</p>
</sec>
<sec id="S9" sec-type="author-contributions">
<title>Author contributions</title>
<p>GZ: investigation, experiments, and writing the draft. FM: algorithm design. ZT: algorithm analysis. YZ: supervision, reviewing, and editing the manuscript. QL: reviewing and editing the manuscript. All authors contributed to the article and approved the submitted version.</p>
</sec>
</body>
<back>
<sec id="S10" sec-type="funding-information">
<title>Funding</title>
<p>This work was supported by National Natural Science Foundation of China under Grant Nos. U21A20464 and 62066005, and Program for Young Innovative Research Team in China University of Political Science and Law, under Grant No. 21CXTD02.</p>
</sec>
<sec id="S11" sec-type="COI-statement">
<title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec id="S12" sec-type="disclaimer">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="B1"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Abualigah</surname> <given-names>L.</given-names></name> <name><surname>Elaziz</surname> <given-names>M. A.</given-names></name> <name><surname>Hussien</surname> <given-names>A. G.</given-names></name> <name><surname>Alsalibi</surname> <given-names>B.</given-names></name> <name><surname>Jafar Jalali</surname> <given-names>S.</given-names></name> <name><surname>Gandomi</surname> <given-names>A.</given-names></name></person-group> (<year>2021</year>). <article-title>Lightning search algorithm: A comprehensive survey.</article-title> <source><italic>Appl. Intell.</italic></source> <volume>51</volume> <fpage>2353</fpage>&#x2013;<lpage>2376</lpage>. <pub-id pub-id-type="doi">10.1007/s10489-020-01947-2</pub-id> <pub-id pub-id-type="pmid">34764558</pub-id></citation></ref>
<ref id="B2"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Aggarwal</surname> <given-names>P.</given-names></name> <name><surname>Sharma</surname> <given-names>S. K.</given-names></name></person-group> (<year>2015</year>). <article-title>Analysis of KDD dataset attributes: Class wise for Intrusion Detection.</article-title> <source><italic>Procedia Comput. Sci.</italic></source> <volume>57</volume> <fpage>842</fpage>&#x2013;<lpage>851</lpage>. <pub-id pub-id-type="doi">10.1016/j.procs.2015.07.490</pub-id></citation></ref>
<ref id="B3"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Askarzadeh</surname> <given-names>A.</given-names></name></person-group> (<year>2016</year>). <article-title>A novel metaheuristic method for solving constrained engineering optimization problems: Crow search algorithm.</article-title> <source><italic>Comput. Struct.</italic></source> <volume>169</volume> <fpage>1</fpage>&#x2013;<lpage>12</lpage>. <pub-id pub-id-type="doi">10.1016/j.compstruc.2016.03.001</pub-id></citation></ref>
<ref id="B4"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Chakraborty</surname> <given-names>S.</given-names></name> <name><surname>Nama</surname> <given-names>S.</given-names></name> <name><surname>Saha</surname> <given-names>A. K.</given-names></name></person-group> (<year>2022</year>). <article-title>An improved symbiotic organisms search algorithm for higher dimensional optimization problems.</article-title> <source><italic>Knowledge-Based Syst.</italic></source> <volume>236</volume>:<issue>107779</issue>. <pub-id pub-id-type="doi">10.1016/j.knosys.2021.107779</pub-id></citation></ref>
<ref id="B5"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Cheng</surname> <given-names>M. Y.</given-names></name> <name><surname>Prayogo</surname> <given-names>D.</given-names></name></person-group> (<year>2014</year>). <article-title>Symbiotic organisms search: A new metaheuristic optimization algorithm.</article-title> <source><italic>Comput. Struct.</italic></source> <volume>139</volume> <fpage>98</fpage>&#x2013;<lpage>112</lpage>. <pub-id pub-id-type="doi">10.1007/s13369-020-05217-8</pub-id> <pub-id pub-id-type="pmid">33520590</pub-id></citation></ref>
<ref id="B6"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>De Almeida</surname> <given-names>C. W. D.</given-names></name> <name><surname>de Souza</surname> <given-names>R. M. C. R.</given-names></name> <name><surname>Candeias</surname> <given-names>A. L. B.</given-names></name></person-group> (<year>2013</year>). <article-title>Fuzzy Kohonen clustering networks for interval data.</article-title> <source><italic>Neurocomputing</italic></source> <volume>99</volume> <fpage>65</fpage>&#x2013;<lpage>75</lpage>. <pub-id pub-id-type="doi">10.1109/TNN.2007.911709</pub-id> <pub-id pub-id-type="pmid">18390309</pub-id></citation></ref>
<ref id="B7"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Derrac</surname> <given-names>J.</given-names></name> <name><surname>Garc&#x00ED;a</surname> <given-names>S.</given-names></name> <name><surname>Molina</surname> <given-names>D.</given-names></name> <name><surname>Herrera</surname> <given-names>F.</given-names></name></person-group> (<year>2011</year>). <article-title>A practical tutorial on the use of nonparametric statistical tests as a methodology for comparing evolutionary and swarm intelligence algorithms.</article-title> <source><italic>Swarm Evol. Comput.</italic></source> <volume>1</volume> <fpage>3</fpage>&#x2013;<lpage>18</lpage>. <pub-id pub-id-type="doi">10.1016/j.swevo.2011.02.002</pub-id></citation></ref>
<ref id="B8"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Ezugwua</surname> <given-names>A. E.</given-names></name> <name><surname>Prayogo</surname> <given-names>D.</given-names></name></person-group> (<year>2019</year>). <article-title>Symbiotic organisms search algorithm: Theory, recent advances and applications.</article-title> <source><italic>Expert Syst. Appl.</italic></source> <volume>119</volume> <fpage>184</fpage>&#x2013;<lpage>209</lpage>. <pub-id pub-id-type="doi">10.1016/j.eswa.2018.10.045</pub-id></citation></ref>
<ref id="B9"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Feng</surname> <given-names>W.</given-names></name> <name><surname>Zhang</surname> <given-names>Q.</given-names></name> <name><surname>Hu</surname> <given-names>G.</given-names></name> <name><surname>Xiang</surname> <given-names>J.</given-names></name> <name><surname>Huang</surname> <given-names>J.</given-names></name></person-group> (<year>2014</year>). <article-title>Mining network data for intrusion detection through combining SVMs with ant colony networks.</article-title> <source><italic>Future Gener. Comput. Syst.</italic></source> <volume>37</volume> <fpage>127</fpage>&#x2013;<lpage>140</lpage>. <pub-id pub-id-type="doi">10.1016/j.future.2013.06.027</pub-id></citation></ref>
<ref id="B10"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Fouad</surname> <given-names>A.</given-names></name> <name><surname>Gao</surname> <given-names>X.</given-names></name></person-group> (<year>2019</year>). <article-title>A novel modified flower pollination algorithm for global optimization.</article-title> <source><italic>Neural Comput. Appl.</italic></source> <volume>31</volume> <fpage>3875</fpage>&#x2013;<lpage>3908</lpage>. <pub-id pub-id-type="doi">10.1007/s00521-017-3313-0</pub-id></citation></ref>
<ref id="B11"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Ganapathy</surname> <given-names>S.</given-names></name> <name><surname>Kulothungan</surname> <given-names>K.</given-names></name> <name><surname>Yogesh</surname> <given-names>P.</given-names></name> <name><surname>Kannan</surname> <given-names>A.</given-names></name></person-group> (<year>2012</year>). <article-title>A novel weighted fuzzy <italic>C</italic>-means clustering based on immune genetic algorithm for intrusion detection.</article-title> <source><italic>Int. Conf. Model. Optim. Comput.</italic></source> <volume>38</volume> <fpage>1747</fpage>&#x2013;<lpage>1750</lpage>. <pub-id pub-id-type="doi">10.1016/j.proeng.2012.06.213</pub-id></citation></ref>
<ref id="B12"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Gibbons</surname> <given-names>J. D.</given-names></name> <name><surname>Chakraborti</surname> <given-names>S.</given-names></name></person-group> (<year>2011</year>). <source><italic>Nonparametric Statistical Inference.</italic></source> <publisher-loc>Berlin</publisher-loc>: <publisher-name>Springer</publisher-name>. <pub-id pub-id-type="doi">10.1201/9781439896129</pub-id></citation></ref>
<ref id="B13"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Hollander</surname> <given-names>M.</given-names></name> <name><surname>Wolfe</surname> <given-names>D. A.</given-names></name> <name><surname>Chicken</surname> <given-names>E.</given-names></name></person-group> (<year>2013</year>). <source><italic>Nonparametric Statistical Methods.</italic></source> <publisher-loc>Hoboken, NJ</publisher-loc>: <publisher-name>John Wiley and Sons</publisher-name>.</citation></ref>
<ref id="B14"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Hussien</surname> <given-names>A. G.</given-names></name> <name><surname>Abualigah</surname> <given-names>L.</given-names></name> <name><surname>Zitar</surname> <given-names>R. A.</given-names></name> <name><surname>Hashim</surname> <given-names>F. A.</given-names></name> <name><surname>Amin</surname> <given-names>M.</given-names></name> <name><surname>Saber</surname> <given-names>A.</given-names></name><etal/></person-group> (<year>2022</year>). <article-title>Recent advances in Harris hawks optimization: A comparative study and applications.</article-title> <source><italic>Electronics</italic></source> <volume>11</volume>:<issue>1919</issue>. <pub-id pub-id-type="doi">10.3390/electronics11121919</pub-id></citation></ref>
<ref id="B15"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Hussien</surname> <given-names>A. G.</given-names></name> <name><surname>Amin</surname> <given-names>M.</given-names></name> <name><surname>Wang</surname> <given-names>M.</given-names></name> <name><surname>Liang</surname> <given-names>G.</given-names></name> <name><surname>Alsanad</surname> <given-names>A.</given-names></name> <name><surname>Gumaei</surname> <given-names>A.</given-names></name><etal/></person-group> (<year>2021</year>). <article-title>Crow search algorithm: Theory, recent advances, and applications.</article-title> <source><italic>IEEE Access</italic></source> <volume>8</volume> <fpage>173548</fpage>&#x2013;<lpage>173565</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2020.3024108</pub-id></citation></ref>
<ref id="B16"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Jordehi</surname> <given-names>A. R.</given-names></name> <name><surname>Jasni</surname> <given-names>J.</given-names></name></person-group> (<year>2015</year>). <article-title>Particle swarm optimisation for discrete optimization problems: A review.</article-title> <source><italic>Artif. Intell. Rev.</italic></source> <volume>43</volume> <fpage>243</fpage>&#x2013;<lpage>258</lpage>. <pub-id pub-id-type="doi">10.1007/s10462-012-9373-8</pub-id></citation></ref>
<ref id="B17"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Kaveh</surname> <given-names>A.</given-names></name> <name><surname>Bakhshpoori</surname> <given-names>T.</given-names></name></person-group> (<year>2016</year>). <article-title>Water evaporation optimization: A novel physically inspired optimization algorithm.</article-title> <source><italic>Comput. Struct.</italic></source> <volume>167</volume> <fpage>69</fpage>&#x2013;<lpage>85</lpage>. <pub-id pub-id-type="doi">10.1016/j.compstruc.2016.01.008</pub-id></citation></ref>
<ref id="B18"><citation citation-type="journal"><collab>KDD Cup 1999 Data</collab> (<year>1999</year>). <source><italic>Information and Computer Science.</italic></source> <publisher-loc>Irvine, CA</publisher-loc>: <publisher-name>University of California</publisher-name>.</citation></ref>
<ref id="B19"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Kennedy</surname> <given-names>J.</given-names></name> <name><surname>Eberhart</surname> <given-names>R.</given-names></name></person-group> (<year>1995</year>). &#x201C;<article-title>Particle swarm optimization</article-title>,&#x201D; in <source><italic>Proceedings of the IEEE International Conference on Neural Networks IV</italic></source>, <publisher-loc>Perth</publisher-loc>.</citation></ref>
<ref id="B20"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Lin</surname> <given-names>W.</given-names></name> <name><surname>Ke</surname> <given-names>S.</given-names></name> <name><surname>Tsai</surname> <given-names>C.</given-names></name></person-group> (<year>2015</year>). <article-title>CANN: An intrusion detection system based on combining cluster centers and nearest neighbors.</article-title> <source><italic>Knowledge-Based Syst.</italic></source> <volume>78</volume> <fpage>13</fpage>&#x2013;<lpage>21</lpage>. <pub-id pub-id-type="doi">10.1016/j.knosys.2015.01.009</pub-id></citation></ref>
<ref id="B21"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Mabu</surname> <given-names>S.</given-names></name> <name><surname>Ci</surname> <given-names>C.</given-names></name> <name><surname>Nannan</surname> <given-names>L.</given-names></name> <name><surname>Shimada</surname> <given-names>K.</given-names></name> <name><surname>Hirasawa</surname> <given-names>K.</given-names></name></person-group> (<year>2011</year>). <article-title>An intrusion-detection model based on fuzzy class-association-rule mining using genetic network programming.</article-title> <source><italic>IEEE Trans. Syst. Man Cybern. Part C Appl. Rev.</italic></source> <volume>41</volume> <fpage>130</fpage>&#x2013;<lpage>139</lpage>. <pub-id pub-id-type="doi">10.1109/TSMCC.2010.2050685</pub-id></citation></ref>
<ref id="B22"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Mirjalili</surname> <given-names>S.</given-names></name> <name><surname>Mirjalili</surname> <given-names>S. M.</given-names></name> <name><surname>Lewis</surname> <given-names>A.</given-names></name></person-group> (<year>2014</year>). <article-title>Grey wolf optimizer.</article-title> <source><italic>Adv. Eng. Software</italic></source> <volume>69</volume> <fpage>46</fpage>&#x2013;<lpage>61</lpage>. <pub-id pub-id-type="doi">10.1016/j.advengsoft.2013.12.007</pub-id></citation></ref>
<ref id="B23"><citation citation-type="journal"><collab>MIT Lincoln Laboratory</collab> (<year>2009</year>). <source><italic>Intrusion detection attacks database.</italic></source> <publisher-loc>Cambridge, MA</publisher-loc>: <publisher-name>MIT Lincoln Laboratory</publisher-name>.</citation></ref>
<ref id="B24"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Mohamed</surname> <given-names>A. W.</given-names></name> <name><surname>Hadi</surname> <given-names>A. A.</given-names></name> <name><surname>Mohamed</surname> <given-names>A. K.</given-names></name></person-group> (<year>2020</year>). <article-title>Gaining-sharing knowledge based algorithm for solving optimization problems: A novel nature-inspired algorithm.</article-title> <source><italic>Int. J. Mach. Learn. Cyber.</italic></source> <volume>11</volume> <fpage>1501</fpage>&#x2013;<lpage>1529</lpage>. <pub-id pub-id-type="doi">10.1007/s13042-019-01053-x</pub-id></citation></ref>
<ref id="B25"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Shareef</surname> <given-names>H.</given-names></name> <name><surname>Ibrahim</surname> <given-names>A. A.</given-names></name> <name><surname>Mutlag</surname> <given-names>A. H.</given-names></name></person-group> (<year>2015</year>). <article-title>Lightning search algorithm.</article-title> <source><italic>Appl. Soft Comput.</italic></source> <volume>36</volume> <fpage>315</fpage>&#x2013;<lpage>333</lpage>. <pub-id pub-id-type="pmid">34764558</pub-id></citation></ref>
<ref id="B26"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Shehab</surname> <given-names>M.</given-names></name> <name><surname>Abu-Hashem</surname> <given-names>M. A.</given-names></name> <name><surname>Shambour</surname> <given-names>M. K. Y.</given-names></name> <name><surname>Alsalibi</surname> <given-names>A.</given-names></name> <name><surname>Alomari</surname> <given-names>O.</given-names></name> <name><surname>Gupta</surname> <given-names>J.</given-names></name><etal/></person-group> (<year>2022</year>). <article-title>A comprehensive review of bat inspired algorithm: Variants, applications, and hybridization.</article-title> <source><italic>Arch. Comput. Methods Eng.</italic></source> <pub-id pub-id-type="doi">10.1007/s11831-022-09817-5</pub-id> <comment>[Epub ahead of print]</comment>. <pub-id pub-id-type="pmid">36157973</pub-id></citation></ref>
<ref id="B27"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Shi</surname> <given-names>J.</given-names></name> <name><surname>Li</surname> <given-names>Z.</given-names></name> <name><surname>Lai</surname> <given-names>W.</given-names></name> <name><surname>Li</surname> <given-names>F.</given-names></name> <name><surname>Shi</surname> <given-names>R.</given-names></name> <name><surname>Feng</surname> <given-names>Y.</given-names></name><etal/></person-group> (<year>2021</year>). &#x201C;<article-title>Two End-to-End Quantum-inspired Deep Neural Networks for Text Classification</article-title>&#x201D; in <source><italic>Proceedings of the IEEE Transactions on Knowledge and Data Engineering</italic></source>, <publisher-loc>Piscataway, NJ</publisher-loc></citation></ref>
<ref id="B28"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Shitharth</surname> <given-names>S.</given-names></name> <name><surname>Winston</surname> <given-names>P. D.</given-names></name></person-group> (<year>2017</year>). <article-title>An enhanced optimization based algorithm for intrusion detection in SCADA network.</article-title> <source><italic>Comput. Secur.</italic></source> <volume>70</volume> <fpage>16</fpage>&#x2013;<lpage>26</lpage>. <pub-id pub-id-type="doi">10.1016/j.cose.2017.04.012</pub-id></citation></ref>
<ref id="B29"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Wang</surname> <given-names>G.</given-names></name> <name><surname>Deb</surname> <given-names>S.</given-names></name> <name><surname>Cui</surname> <given-names>Z. H.</given-names></name></person-group> (<year>2019</year>). <article-title>Monarch butterfly optimization.</article-title> <source><italic>Neural Comput. Appl.</italic></source> <volume>31</volume> <fpage>1995</fpage>&#x2013;<lpage>2014</lpage>. <pub-id pub-id-type="doi">10.1007/s00521-015-1923-y</pub-id></citation></ref>
<ref id="B30"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Wehrens</surname> <given-names>R.</given-names></name> <name><surname>Buydens</surname> <given-names>L. M. C.</given-names></name></person-group> (<year>2007</year>). <article-title>Self-and Super-organising Maps in R: The Kohonen package.</article-title> <source><italic>J. Stat. Software</italic></source> <volume>21</volume> <fpage>1</fpage>&#x2013;<lpage>19</lpage>.</citation></ref>
<ref id="B31"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Wolpert</surname> <given-names>D. H.</given-names></name> <name><surname>Macready</surname> <given-names>W. G.</given-names></name></person-group> (<year>1997</year>). <article-title>No free lunch theorems for optimization.</article-title> <source><italic>IEEE Trans. Evol. Comput.</italic></source> <volume>1</volume> <fpage>67</fpage>&#x2013;<lpage>82</lpage>. <pub-id pub-id-type="doi">10.1109/4235.585893</pub-id></citation></ref>
<ref id="B32"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Xinshe</surname> <given-names>Y.</given-names></name></person-group> (<year>2010</year>). &#x201C;<article-title>A new metaheuristic bat-inspired algorithm</article-title>,&#x201D; in <source><italic>Nature Inspired Cooperative Strategies for Optimization</italic></source>, <role>eds</role> <person-group person-group-type="editor"><name><surname>Gonzalez</surname> <given-names>J. R.</given-names></name> <name><surname>Pelta</surname> <given-names>D. A.</given-names></name> <name><surname>Cruz</surname> <given-names>C.</given-names></name></person-group> (<publisher-loc>Berlin</publisher-loc>: <publisher-name>Springer-Verlag</publisher-name>), <fpage>65</fpage>&#x2013;<lpage>74</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-642-12538-6_6</pub-id></citation></ref>
<ref id="B33"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Yang</surname> <given-names>X. S.</given-names></name></person-group> (<year>2012</year>). &#x201C;<article-title>Flower pollination algorithm for global optimization</article-title>,&#x201D; in <source><italic>Unconventional Computation and Natural Computation, Lecture Notes in Computer Science</italic></source>, <volume>Vol. 7445</volume> <role>eds</role> <person-group person-group-type="editor"><name><surname>Patitz</surname> <given-names>M. J.</given-names></name> <name><surname>Stannett</surname> <given-names>M.</given-names></name></person-group> (<publisher-loc>Berlin</publisher-loc>: <publisher-name>Springer</publisher-name>), <fpage>240</fpage>&#x2013;<lpage>249</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-642-32894-7_27</pub-id></citation></ref>
<ref id="B34"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Yang</surname> <given-names>X. S.</given-names></name> <name><surname>Deb</surname> <given-names>S.</given-names></name></person-group> (<year>2009</year>). &#x201C;<article-title>Cuckoo search via Levy flights</article-title>,&#x201D; in <source><italic>Proceedings of the World Congress on Nature &#x0026; Biologically Inspired Computing (NaBIC 2009)</italic></source>, <publisher-loc>Piscataway, NJ</publisher-loc>. <pub-id pub-id-type="doi">10.1155/2022/5443160</pub-id> <pub-id pub-id-type="pmid">36081607</pub-id></citation></ref>
<ref id="B35"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Zhang</surname> <given-names>L.</given-names></name> <name><surname>Bai</surname> <given-names>Z.</given-names></name> <name><surname>Lu</surname> <given-names>Y.</given-names></name> <name><surname>Zha</surname> <given-names>Y.</given-names></name> <name><surname>Li</surname> <given-names>Z.</given-names></name></person-group> (<year>2014</year>). <article-title>Integrated intrusion detection model based on artificial immune.</article-title> <source><italic>J. China Univ. Posts Telecommun.</italic></source> <volume>21</volume> <fpage>83</fpage>&#x2013;<lpage>90</lpage>. <pub-id pub-id-type="doi">10.1016/S1005-8885(14)60290-9</pub-id></citation></ref>
</ref-list>
</back>
</article>
