Nearest neighbors based density peaks approach to intrusion detection

Nearest neighbors based density peaks approach to intrusion detection
复制标题

基于最近邻的密度峰值方法进行入侵检测

DOI:
10.1016/j.chaos.2018.03.010
复制
发表时间:
2018-05-01
影响因子:
7.8
通讯作者:
Yang, Yixian
Yang, Yixian
中科院分区:
数学1区
文献类型:
--
作者:
Li, Lixiang;Zhang, Hao;Yang, Yixian

文献摘要

被引文献

相似文献

入侵检测系统对网络安全具有重要意义。然而,传统的入侵检测系统无法识别零日攻击等新型网络入侵行为。在入侵检测系统中使用了许多机器学习技术,它们表现出了比其他方法更好的检测性能。提出了一种不需要太多参数的密度峰值聚类(DPC)算法,其迭代过程是基于密度的。由于其步骤和参数简单,可能会有很多应用领域。因此,我们将把它应用于入侵检测中,寻找一种更准确、更高效的分类器。为了更有效地检测攻击,并在k-近邻网络中引入密度,在DPC的基础上提出了一种基于k-近邻的混合学习模型。在密度峰最近邻(DPNN)中,使用入侵检测的标准数据集KDD-CUP 99进行实验。然后,我们使用该数据集来训练和计算该算法中使用的一些参数。最后,利用DPNN分类器对攻击进行分类。实验结果表明,DPNN的性能优于支持向量机、k近邻等多种机器学习方法,能够有效地检测入侵攻击,并具有较好的准确率。(C)2018爱思唯尔有限公司。保留所有权利。
Intrusion detection systems are very important for network security. However, traditional intrusion detection systems can not identify new type of network intrusion for example zero-day attack. Many machine learning techniques were used in intrusion detection system and they showed better detection performance than other methods. A novel clustering algorithm called Density peaks clustering (DPC) which does not need many parameters and its iterative process is based on density. Because of its simple steps and parameters, it may have many application fields. So we are going to use it in intrusion detection to find a more accurate and efficient classifier. On the basis of some good ideas of DPC, this paper proposes a hybrid learning model based on k-nearest neighbors (kNN) in order to detect attacks more effectively and introduce the density in kNN. In density peaks nearest neighbors (DPNN), KDD-CUP 99 which is the standard dataset in intrusion detection is used to the experiment. Then, we use the dataset to train and calculate some parameters which are used in this algorithm. Finally, the DPNN classifier is used to classify attacks. Experiment results suggest that the DPNN performs better than support vector machine (SVM), k-nearest neighbors (kNN) and many other machine learning methods, and it can effectively detect intrusion attacks and has a good performance in accuracy. (c) 2018 Elsevier Ltd. All rights reserved.