Another Fuzzy Anomaly Detection System Based on Ant Clustering Algorithm

被引:16
作者
Aminanto, Muhamad Erza [1 ]
Kim, HakJu [1 ]
Kim, Kyung-Min [1 ]
Kim, Kwangjo [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
关键词
unknown attacks; unsupervised learning; ant clustering algorithm; fuzzy logic; INTRUSION DETECTION;
D O I
10.1587/transfun.E100.A.176
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Attacks against computer networks are evolving rapidly. Conventional intrusion detection system based on pattern matching and static signatures have a significant limitation since the signature database should be updated frequently. The unsupervised learning algorithm can overcome this limitation. Ant Clustering Algorithm (ACA) is a popular unsupervised learning algorithm to classify data into different categories. However, ACA needs to be complemented with other algorithms for the classification process. In this paper, we present a fuzzy anomaly detection system that works in two phases. In the first phase, the training phase, we propose ACA to determine clusters. In the second phase, the classification phase, we exploit a fuzzy approach by the combination of two distance based methods to detect anomalies in new monitored data. We validate our hybrid approach using the KDD Cup'99 dataset. The results indicate that, compared to several traditional and new techniques, the proposed hybrid approach achieves higher detection rate and lower false positive rate.
引用
收藏
页码:176 / 183
页数:8
相关论文
共 19 条
  • [1] Abadeh MS, 2010, ISECURE-ISC INT J IN, V2, P33
  • [2] Albuquerque P, 2002, LECT NOTES COMPUT SC, V2493, P220
  • [3] [Anonymous], 2006, Swarm Intelligence in Data Mining
  • [4] Hosseinpour F., 2014, International Journal of Digital Content Technology and its Applications, V8, P1
  • [5] Agreement-based fuzzy C-means for clustering data with blocks of features
    Izakian, Hesam
    Pedrycz, Witold
    [J]. NEUROCOMPUTING, 2014, 127 : 266 - 280
  • [6] Kanade PM, 2003, NAFIPS'2003: 22ND INTERNATIONAL CONFERENCE OF THE NORTH AMERICAN FUZZY INFORMATION PROCESSING SOCIETY - NAFIPS PROCEEDINGS, P227
  • [7] A fuzzy anomaly detection system based on hybrid PSO-Kmeans algorithm in content-centric networks
    Karami, Amin
    Guerrero-Zapata, Manel
    [J]. NEUROCOMPUTING, 2015, 149 : 1253 - 1269
  • [8] Kim K.-M., 2015, P COMP SEC S 2015 CS, P64
  • [9] Swarm intelligence in intrusion detection: A survey
    Kolias, C.
    Kambourakis, G.
    Maragoudakis, M.
    [J]. COMPUTERS & SECURITY, 2011, 30 (08) : 625 - 642
  • [10] Laskov P, 2005, LECT NOTES COMPUT SC, V3617, P50, DOI 10.1007/11553595_6