Labelling Clusters in an Intrusion Detection System Using a Combination of Clustering Evaluation Techniques

Labelling Clusters in an Intrusion Detection System Using a Combination of Clustering Evaluation Techniques
复制标题

DOI:
10.1109/hicss.2006.247
复制
发表时间:
2006-01
期刊:
Proceedings of the 39th Annual Hawaii International Conference on System Sciences (HICSS'06)
影响因子:
--
通讯作者:
Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera
Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera
中科院分区:
其他
文献类型:
--
作者:
Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera

文献摘要

被引文献

相似文献

提出了一种新的聚类标记策略,该策略将聚类的Davies-Bouldin指数和聚类的质心直径计算结合起来,应用于基于异常的入侵检测系统(IDS)中。这种策略的目的是检测包含非常相似的向量的紧凑集群,这些集群很可能是攻击向量。实验结果表明,该方法在大规模攻击环境下的性能优于传统的基于基数标记的入侵检测系统。标记算法的参数可以变化,以适应被监控网络中的条件。
A new clusters labelling strategy, which combines the computation of the Davies-Bouldin index of the clustering and the centroid diameters of the clusters is proposed for application in anomaly based intrusion detection systems (IDS). The aim of such a strategy is to detect compact clusters containing very similar vectors and these are highly likely to be attack vectors. Experimental results comparing the effectiveness of a multiple classifier IDS with such a labelling strategy and that of the classical cardinality labelling based IDS show that the proposed strategy behaves much better in a heavily attacked environment where massive attacks are present. The parameters of the labelling algorithm can be varied in order to adapt to the conditions in the monitored network.