Labelling Clusters in an Intrusion Detection System Using a Combination of Clustering Evaluation Techniques
Labelling Clusters in an Intrusion Detection System Using a Combination of Clustering Evaluation Techniques
复制标题
DOI:
10.1109/hicss.2006.247
复制
发表时间:
2006-01
期刊:
影响因子:
--
通讯作者:
Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera
中科院分区:
文献类型:
--
作者:
Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera
A new clusters labelling strategy, which combines the computation of the Davies-Bouldin index of the clustering and the centroid diameters of the clusters is proposed for application in anomaly based intrusion detection systems (IDS). The aim of such a strategy is to detect compact clusters containing very similar vectors and these are highly likely to be attack vectors. Experimental results comparing the effectiveness of a multiple classifier IDS with such a labelling strategy and that of the classical cardinality labelling based IDS show that the proposed strategy behaves much better in a heavily attacked environment where massive attacks are present. The parameters of the labelling algorithm can be varied in order to adapt to the conditions in the monitored network.