 Zheng Miaomiao,Ji Genlin.An Unsupervised Anomaly Intrusion Detection for the Mixed Attributes[J].Journal of Nanjing Normal University(Engineering and Technology),2008,08(02):068-73.





An Unsupervised Anomaly Intrusion Detection for the Mixed Attributes
南京师范大学数学与计算机科学学院, 江苏南京210097
Zheng MiaomiaoJi Genlin
School of Mathematics and Computer Science,Nanjing Normal University,Nanjing 210097,China
入侵检测 聚类 混合型属性
intrusion de tection c lustering m ix ed attributes
The cu rrent intrusion detec tion techniques can no t analyze the attributes com posed by ca tego rica l and suffer h igher fa lse detec tion rate. In th is paper, an e ffective anoma ly detection algorithm based on cluster ing is proposed to deal w ith m ixed a ttr ibu tes. Th is algor ithm, which ge ts c lusterm ode ls by using the c lustering a lgo rithm on un labeled training data, de fines the d istance betw een each pa ir of va lues in one catego rical attr ibute, can deal w ith both the num er ica l and ca tego rical attr ibute e fficiently. Theo re tica l analysis shows that it ho lds no t on ly the essence be tw een d ifferen t values in one categor ica l a ttribute, but a lso the orig inal dim ens ions of the dataset. A t last, expe rim en ts on the KDD-CUP-99 data records of netwo rk connections show that ourm ethod can detect in trusions m ore effic iently wh ile ma inta in ing a low fa lse positive ra te


