Real-Time Intrusion Detection System Based on Self-Organized Maps and Feature Correlations

Real-Time Intrusion Detection System Based on Self-Organized Maps and Feature Correlations
复制标题

基于自组织映射和特征相关性的实时入侵检测系统

DOI:
10.1109/iccit.2008.362
复制
发表时间:
2008
期刊:
2008 Third International Conference on Convergence and Hybrid Information Technology
影响因子:
--
通讯作者:
K. Chae
K. Chae
中科院分区:
--
文献类型:
--
作者:
Hayoung Oh;K. Chae

文献摘要

被引文献

相似文献

网络入侵检测一直是网络安全研究的重点和难点。由于网络入侵模式和特征的时间变化,传统的监督学习技术不适合检测异常行为和新的攻击。因此,无监督学习技术,如SOM(自组织映射)更适合异常检测。在本文中,我们提出了一个实时的入侵检测系统的基础上,SOM集团相似的数据和可视化的集群。我们的系统标签的SOM使用功能之间的相关性产生的地图。我们用KDD Cup 1999数据集对系统进行了实验。我们的系统产生合理的错误分类率,并需要0.5秒来决定一个行为是正常的还是攻击。
Detecting network intrusion has been not only critical but also difficult in the network security research area. Traditional supervised learning techniques are not appropriate to detect anomalous behaviors and new attacks because of temporal changes in network intrusion patterns and characteristics. Therefore, unsupervised learning techniques such as SOM (self-organizing map) are more appropriate for anomaly detection. In this paper, we proposed a real-time intrusion detection system based on SOM that groups similar data and visualize their clusters. Our system labels the map produced by SOM using correlations between features. We experiments our system with KDD Cup 1999 data set. Our system yields the reasonable misclassification rates and takes 0.5 seconds to decide whether a behavior is normal or attack.