An unsupervised anomaly detection approach using subtractive clustering and Hidden Markov Model

被引:0
|
作者
Yang, Chun [1 ]
Deng, Feiqi [1 ]
Yang, Haidong [1 ]
机构
[1] S China Univ Technol, Coll Automat Sci & Engn, Guangzhou 510640, Guangdong, Peoples R China
关键词
subtractive clustering; Hidden Markov Model; feature selection; intrusion detection;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Previous Research in network intrusion detection system (NIDS) has typically used misuse detection or supervised anomaly detection techniques. These techniques have difficulty in detecting new types of attacks or causing high false positives in real network environment. Unsupervised anomaly detection can overcome the drawbacks of misuse detection and supervised anomaly detection. In this paper, normal-anomaly patterns are built over the network traffic dataset that uses subtractive clustering, and at the same time the built Hidden Markov Model (HMM) correlates the observation sequences and state transitions to predict the most probable intrusion state sequences. The proposed unsupervised anomaly detection approach is capable of reducing false positives by classifying intrusion sequences into different emergency levels. The experimental results are also reported using the KDDCup'99 dataset and Matlab.
引用
收藏
页码:123 / 126
页数:4
相关论文
共 50 条
  • [1] ADAPTIVE ANOMALY DETECTION USING A HIDDEN MARKOV MODEL
    Lee, Seungchul
    Li, Lin
    Ni, Jun
    PROCEEDINGS OF THE ASME INTERNATIONAL MANUFACTURING SCIENCE AND ENGINEERING CONFERENCE 2010, VOL 2, 2011, : 599 - 606
  • [2] ANOMALY NETWORK INTRUSION DETECTION USING HIDDEN MARKOV MODEL
    Chen, Chia-Mei
    Guan, Dah-Jyh
    Huang, Yu-Zhi
    Ou, Ya-Hui
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2016, 12 (02): : 569 - 580
  • [3] Workload hidden Markov model for anomaly detection
    Garcia, Juan Manuel
    Navarrete, Tomas
    Orozco, Carlos
    SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : 56 - +
  • [4] Unknown Anomaly Detection Using Hidden Markov Model and AreaSensing Techniques
    Kurahashi, Setsuya
    Ono, Isao
    TETSU TO HAGANE-JOURNAL OF THE IRON AND STEEL INSTITUTE OF JAPAN, 2020, 106 (02): : 91 - 99
  • [5] Unsupervised anomaly intrusion detection using ant colony clustering model
    Tsang, W
    Kwong, S
    Soft Computing as Transdisciplinary Science and Technology, 2005, : 223 - 232
  • [6] Unsupervised scene analysis: A hidden Markov model approach
    Bicego, M
    Cristani, M
    Murino, V
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2006, 102 (01) : 22 - 41
  • [7] Hidden Markov Anomaly Detection
    Goerntiz, Nico
    Braun, Mikio
    Kloft, Marius
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 37, 2015, 37 : 1833 - 1842
  • [8] Hidden semi-Markov model for anomaly detection
    Tan, Xiaobin
    Xi, Hongsheng
    APPLIED MATHEMATICS AND COMPUTATION, 2008, 205 (02) : 562 - 567
  • [9] Hidden Markov Model Based Anomaly Intrusion Detection
    Jain, Ruchi
    Abouzakhar, Nasser S.
    2012 INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS, 2012, : 528 - 533
  • [10] Unsupervised anomaly detection in peripheral venous pressure signals with hidden Markov models
    Abul Hayat, Md
    Wu, Jingxian
    Bonasso, Patrick C.
    Sexton, Kevin W.
    Jensen, Hanna K.
    Dassinger, Melvin S.
    Jensen, Morten O.
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2020, 62 (62)