Y-means: A clustering method for intrusion detection

被引:0
|
作者
Guan, Y [1 ]
Ghorbani, AA [1 ]
Belacel, N [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Fredericton, NB E3B 5A3, Canada
来源
CCECE 2003: CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-3, PROCEEDINGS: TOWARD A CARING AND HUMANE TECHNOLOGY | 2003年
关键词
clustering; intrusion detection; K-means; outlier;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As the Internet spreads to each corner of the world, computers are exposed to miscellaneous intrusions from the World Wide Web. We need effective intrusion detection systems to protect our computers from these unauthorized or malicious actions. Traditional instance-based learning methods for Intrusion Detection can only detect known intrusions since these methods classify instances based on what they have learned They rarely detect the intrusions that they have not learned before. In this paper we present a clustering heuristic for intrusion detection, called Y-means. This proposed heuristic is based on the K-means algorithm and other related clustering algorithms. It overcomes two shortcomings of K-means: number of clusters dependency and degeneracy. The result of simulations run on the KDD-99 data set shows that Y-means is an effective method for partitioning large data space. A detection rate of 89.89% and a false alarm rate of 1.00% are achieved with Y-means.
引用
收藏
页码:1083 / 1086
页数:4
相关论文
共 50 条
  • [1] Y-Means: An Autonomous Clustering Algorithm
    Ghorbani, Ali A.
    Onut, Iosif-Viorel
    HYBRID ARTIFICIAL INTELLIGENCE SYSTEMS, PT 1, 2010, 6076 : 1 - 13
  • [2] A genetic clustering method for intrusion detection
    Liu, YG
    Chen, KF
    Liao, XF
    Zhang, W
    PATTERN RECOGNITION, 2004, 37 (05) : 927 - 942
  • [3] An ensemble clustering method for intrusion detection
    Wankhade, Kapil K.
    Jondhale, Kalpana C.
    INTERNATIONAL JOURNAL OF INTELLIGENT ENGINEERING INFORMATICS, 2019, 7 (2-3) : 112 - 140
  • [4] An unsupervised intrusion detection method combined clustering with simulated annealing
    Ni, Lin
    Zheng, Hong-Ying
    DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2007, 14 : 255 - 258
  • [5] An anomaly intrusion detection method by clustering normal user behavior
    Oh, SH
    Lee, WS
    COMPUTERS & SECURITY, 2003, 22 (07) : 596 - 612
  • [6] A Clustering-Based Method for Intrusion Detection in Web Servers
    Pereira, Hermano
    Jamhour, Edgard
    2013 20TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2013,
  • [7] Intrusion Detection with K-Means Clustering and OneR Classification
    Muda, Z.
    Yassin, W.
    Sulaiman, M. N.
    Udzir, N. I.
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2012, 7 (06): : 347 - 354
  • [8] Improved K-means clustering algorithm in intrusion detection
    Xiao, ShiSong
    Li, XiaoXu
    Liu, XueJiao
    2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 2, 2008, : 771 - 775
  • [9] A clustering algorithm for intrusion detection
    Wang, Q
    Megalooikonomou, V
    DATA MINING, INTRUSION DETECTION, INFORMATION ASSURANCE, AND DATA NETWORKS SECURITY 2005, 2005, 5812 : 31 - 38
  • [10] Intrusion Detection Based on MinMax K-means Clustering
    Eslamnezhad, Mohsen
    Varjani, Ali Yazdian
    2014 7TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2014, : 804 - 808