Unsupervised Anomaly Detection for Network Flow Using Immune Network Based K-means Clustering

Unsupervised Anomaly Detection for Network Flow Using Immune Network Based K-means Clustering
复制标题

使用基于免疫网络的 K 均值聚类对网络流进行无监督异常检测

DOI:
10.1007/978-981-10-6385-5_33
复制
发表时间:
2017-09
期刊:
Journal of Computational Information Systems
影响因子:
--
通讯作者:
Yu Zhang
Yu Zhang
中科院分区:
其他
文献类型:
--
作者:
Yuanquan Shi;Xiaoning Peng;Renfa Li;Yu Zhang

文献摘要

参考文献

相似文献

为了有效检测网络流量中未知的异常攻击行为,提出了一种基于免疫网络K均值聚类的网络流量无监督异常检测方法(UADINK).在UADINK中,引入基于人工免疫网络的K-means聚类算法(aiNet_KMC)对网络流进行聚类,即从网络流中提取抽象的内部图像,通过aiNet模型得到K-means的优化参数K,并利用K-means算法对网络流进行聚类。引入簇标记算法(clusLA)和网络流异常检测算法(NFAD)检测网络流的异常攻击行为,其中clusLA算法用于标记每个簇是否属于恶意,NFAD将标记后的簇作为检测器识别异常网络流。为了评估UADINK的有效性,ISCX 2012 IDS数据集被认为是模拟实验数据集。通过与基于NDM的K-means异常检测方法的比较,结果表明UADINK是一种激进的网络流异常检测方法。
To detect effectively unknown anomalous attack behaviors of network traffic, an Unsupervised Anomaly Detection approach for network flow using Immune Network based K-means clustering (UADINK) is proposed. In UADINK, artificial immune network based K-means clustering algorithm (aiNet_KMC) is introduced to cluster network flow, i.e. extracting abstract internal images from network flows and obtaining an optimizing parameterKof K-means by aiNet model, and network flows are clustered by K-means algorithm. The cluster labeling algorithm (clusLA) and the network flow anomaly detection algorithm (NFAD) are introduced to detect anomalous attack behaviors of network flows, where the clusLA algorithm is used for labeling whether each cluster belongs to malicious, and the labeled clusters are regarded as detectors to identify anomaly network flows by NFAD. To evaluate the effectiveness of UADINK, the ISCX 2012 IDS dataset is considered as the simulating experimental dataset. Compared with the NDM based K-means anomaly detection approach, the results show that UADINK is a radical anomaly detection approach in order to detect anomalies of network flows.
DOI: 10.1109/hicss.2006.247
发表时间: 2006-01
期刊: Proceedings of the 39th Annual Hawaii International Conference on System Sciences (HICSS'06)
影响因子: --
作者:
Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera
通讯作者: Slobodan V. Petrovic;Gonzalo Álvarez;A. Orfila;J. Rubiera
DOI: 10.1109/ntms.2011.5720582
发表时间: 2011-02
期刊: 2011 4th IFIP International Conference on New Technologies, Mobility and Security
影响因子: --
作者:
Philipp Winter;Eckehard Hermann;M. Zeilinger
通讯作者: Philipp Winter;Eckehard Hermann;M. Zeilinger
DOI: 10.6138/jit.2016.17.3.20130405
发表时间: 2016-05
影响因子: 1.6
作者:
Yuanquan Shi;Renfa Li;Xiaoning Peng;Guangxue Yue
通讯作者: Yuanquan Shi;Renfa Li;Xiaoning Peng;Guangxue Yue
DOI: 10.1109/surv.2010.032210.00054
发表时间: 2010-01-01
影响因子: 35.6
作者:
Sperotto, Anna;Schaffrath, Gregor;Stiller, Burkhard
通讯作者: Stiller, Burkhard
DOI: 10.1016/j.tcs.2008.02.011
发表时间: 2008-08-20
影响因子: 1.1
作者:
Timmis, J.;Hone, A.;Clark, E.
通讯作者: Clark, E.