A new intrusion detection method based on SVM with minimum within-class scatter

被引:21
作者
An, Wenjuan [1 ,2 ]
Liang, Mangui [1 ,2 ]
机构
[1] Beijing Jiaotong Univ, Inst Informat Sci, Beijing 100044, Peoples R China
[2] Beijing Key Lab Adv Informat Sci & Network Techno, Beijing 100044, Peoples R China
关键词
intrusion detection systems; prior knowledge; support vector machine; within-class scatter;
D O I
10.1002/sec.666
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection has become an indispensable technique to ensure the security and reliability of information systems. Support vector machine (SVM) and its many improved algorithms have been successfully applied to intrusion detection systems in recent years. However, the training process of SVM ignores an important prior knowledge, the within-class structure in the training set. In this paper, we propose an improved classification algorithm, which combines minimum within-class scatter in Fisher discriminant analysis with traditional SVM. The central idea is to find an optimal separating hyperplane such that the margin is maximized, whereas the within-class scatter is kept as small as possible. This new algorithm is called SVM with minimum within-class scatter (WCS-SVM). A set of experiments is conducted on ten benchmarking datasets and KDDCUP'99 experimental data of MIT Lincoln Laboratory to test the generalization performance of the WCS-SVM algorithm. Experimental results show that the WCS-SVM algorithm has better discriminatory power than traditional SVM and kernel Fisher discriminant analysis and it has higher true detection rate and lower false positive rate for intrusion detection systems. Copyright (c) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1064 / 1074
页数:11
相关论文
共 24 条
[1]  
[Anonymous], 2006, Pattern recognition and machine learning
[2]   Intrusion detection through learning behavior model [J].
Balajinath, B ;
Raghavan, SV .
COMPUTER COMMUNICATIONS, 2001, 24 (12) :1202-1212
[3]   Generalized discriminant analysis using a kernel approach [J].
Baudat, G ;
Anouar, FE .
NEURAL COMPUTATION, 2000, 12 (10) :2385-2404
[4]  
Belkin M, 2004, TR200406 U CHIC DEP
[5]  
[陈才扣 CHEN Caikou], 2007, [中国图象图形学报, Journal of Image and Graphics], V12, P2143
[6]  
Cherkassky V, 1997, IEEE Trans Neural Netw, V8, P1564, DOI 10.1109/TNN.1997.641482
[7]   SUPPORT-VECTOR NETWORKS [J].
CORTES, C ;
VAPNIK, V .
MACHINE LEARNING, 1995, 20 (03) :273-297
[8]  
Cucker F, 2002, B AM MATH SOC, V39, P1
[9]  
DEBAR H, 1992, P IEEE COMP SOC S RE
[10]  
Du H, 2009 INT C ART INT C