A novel intrusion detection system based on hierarchical clustering and support vector machines

被引:263
作者
Horng, Shi-Jinn [1 ,3 ]
Su, Ming-Yang [4 ]
Chen, Yuan-Hsin [3 ]
Kao, Tzong-Wann [2 ]
Chen, Rong-Jian [3 ]
Lai, Jui-Lin [3 ]
Perkasa, Citra Dwi [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Comp Sci & Informat Engn, Taipei 106, Taiwan
[2] No Taiwan Inst Sci & Technol, Dept Elect Engn, Taipei, Taiwan
[3] Natl United Univ, Dept Elect Engn, Miaoli, Taiwan
[4] Ming Chuan Univ, Dept Comp Sci & Informat Engn, Tao Yuan, Taiwan
关键词
Network intrusion detection system (NIDS); Support vector machines (SVMs); Hierarchical clustering algorithm; KDD Cup 1999; Network security; Data mining;
D O I
10.1016/j.eswa.2010.06.066
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This study proposed an SVM-based intrusion detection system, which combines a hierarchical clustering algorithm, a simple feature selection procedure, and the SVM technique. The hierarchical clustering algorithm provided the SVM with fewer, abstracted, and higher-qualified training instances that are derived from the KDD Cup 1999 training set. It was able to greatly shorten the training time, but also improve the performance of resultant SVM. The simple feature selection procedure was applied to eliminate unimportant features from the training set so the obtained SVM model could classify the network traffic data more accurately. The famous KDD Cup 1999 dataset was used to evaluate the proposed system. Compared with other intrusion detection systems that are based on the same dataset, this system showed better performance in the detection of DoS and Probe attacks, and the beset performance in overall accuracy. (c) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:306 / 313
页数:8
相关论文
共 21 条
  • [1] Abraham A., 2007, Int. J. Netw. Secur, V4, P328
  • [2] [Anonymous], PRACTICAL GUIDE SUPP
  • [3] BOUZIDA Y, 2006, NEURAL NETWORKS VS D
  • [4] CHIMPHLEE W, 2006, P INT C HYBR INF TEC
  • [5] Guha S., 1998, SIGMOD Record, V27, P73, DOI 10.1145/276305.276312
  • [6] ROCK: A robust clustering algorithm for categorical attributes
    Guha, S
    Rastogi, R
    Shim, K
    [J]. 15TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING, PROCEEDINGS, 1999, : 512 - 521
  • [7] Chameleon: Hierarchical clustering using dynamic modeling
    Karypis, G
    Han, EH
    Kumar, V
    [J]. COMPUTER, 1999, 32 (08) : 68 - +
  • [8] *KDD CUP, 1999, INTR DET DAT SET
  • [9] A new intrusion detection system using support vector machines and hierarchical clustering
    Khan, Latifur
    Awad, Mamoun
    Thuraisingham, Bhavani
    [J]. VLDB JOURNAL, 2007, 16 (04) : 507 - 521
  • [10] Levin I., 2000, SIGKDD Explorations, V1, P67, DOI [10.1145/846183.846201, DOI 10.1145/846183.846201]