A fuzzy anomaly detection system based on hybrid PSO-Kmeans algorithm in content-centric networks

A fuzzy anomaly detection system based on hybrid PSO-Kmeans algorithm in content-centric networks
复制标题

DOI:
10.1016/j.neucom.2014.08.070
复制
发表时间:
2015-02-03
期刊:
影响因子:
6
通讯作者:
Guerrero-Zapata, Manel
Guerrero-Zapata, Manel
中科院分区:
计算机科学2区
文献类型:
--
作者:
Karami, Amin;Guerrero-Zapata, Manel

文献摘要

被引文献

相似文献

在以内容为中心的网络(ccn)中,从拒绝服务(DoS)到隐私攻击等新的攻击和安全挑战将会出现。需要一种高效的安全机制来保护内容和防御未知的新形式的攻击和异常。通常,聚类算法可以满足构建良好异常检测系统的要求。K-means是一种常用的异常检测方法,用于将数据划分为不同的类别。然而,该方法存在局部收敛性和对聚类质心选择的敏感性。本文提出了一种新的分两阶段工作的模糊异常检测系统。在第一阶段,即训练阶段,我们提出了一种混合粒子群算法(PSO)和K-means算法,同时使用两个代价函数作为分离良好的聚类和局部优化来确定最优聚类数量。当确定了簇质心和对象的最佳位置后,进入第二阶段。在这一阶段——检测阶段——我们采用一种模糊方法,结合两种基于距离的方法作为分类和离群值来检测新的监测数据中的异常。实验结果表明,与其他已知的聚类算法相比,该算法可以实现最优聚类数量、良好分离的聚类,同时提高了高检出率,降低了误报率。(c) 2014 Elsevier B.V.版权所有
In Content-Centric Networks (CCNs) as a possible future Internet, new kinds of attacks and security challenges - from Denial of Service (DoS) to privacy attacks - will arise. An efficient and effective security mechanism is required to secure content and defense against unknown and new forms of attacks and anomalies. Usually, clustering algorithms would fit the requirements for building a good anomaly detection system. K-means is a popular anomaly detection method to classify data into different categories. However, it suffers from the local convergence and sensitivity to selection of the cluster centroids. In this paper, we present a novel fuzzy anomaly detection system that works in two phases. In the first phase - the training phase - we propose an hybridization of Particle Swarm Optimization (PSO) and K-means algorithm with two simultaneous cost functions as well-separated clusters and local optimization to determine the optimal number of clusters. When the optimal placement of clusters centroids and objects are defined, it starts the second phase. In this phase - the detection phase - we employ a fuzzy approach by the combination of two distance-based methods as classification and outlier to detect anomalies in new monitoring data. Experimental results demonstrate that the proposed algorithm can achieve to the optimal number of clusters, well-separated clusters, as well as increase the high detection rate and decrease the false positive rate at the same time when compared to some other well-known clustering algorithms. (c) 2014 Elsevier B.V. All rights reserved.