Self-adaptive and dynamic clustering for online anomaly detection

被引:40
|
作者
Lee, Seungmin [2 ]
Kim, Gisung [1 ]
Kim, Sehun [3 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Informat Technol, Dept Ind & Syst Engn, Internet Secur Lab, Taejon 305701, South Korea
[2] ETRI, Informat Secur Res Div, Taejon 305700, South Korea
[3] Korea Adv Inst Sci & Technol, Grad Sch Informat Secur, Taejon 305701, South Korea
关键词
Self-organizing map; K-means clustering; Online anomaly detection;
D O I
10.1016/j.eswa.2011.05.058
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As recent Internet threats are evolving more rapidly than ever before, one of the major challenges in designing an intrusion detection system is to provide early and accurate detection of emerging threats. In this study, a novel framework is developed for fully unsupervised training and online anomaly detection. The framework is designed so that an initial model is constructed and then it gradually evolves according to the current state of online data without any human intervention. In the framework, a self-organizing map (SOM) that is seamlessly combined with K-means clustering is transformed into an adaptive and dynamic algorithm suitable for real-time processing. The performance of the proposed approach is evaluated through experiments using the well-known KDD Cup 1999 data set and further experiments using the honeypot data recently collected from Kyoto University. It is shown that the proposed approach can significantly increase the detection rate while the false alarm rate remains low. In particular, it is capable of detecting new types of attacks at the earliest possible time. (C) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:14891 / 14898
页数:8
相关论文
共 50 条
  • [1] Self-adaptive cloud monitoring with online anomaly detection
    Wang, Tao
    Xu, Jiwei
    Zhang, Wenbo
    Gu, Zeyu
    Zhong, Hua
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 80 : 89 - 101
  • [2] A Semi-supervised Approach for Industrial Anomaly Detection via Self-adaptive Clustering
    Ma, Xiaoxue
    Keung, Jacky
    He, Pinjia
    Xiao, Yan
    Yu, Xiao
    Li, Yishu
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (02) : 1687 - 1697
  • [3] Self-adaptive kernel machine: Online clustering in RKHS
    Boubacar, HA
    Lecoeuche, S
    Maouche, S
    PROCEEDINGS OF THE INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), VOLS 1-5, 2005, : 1977 - 1982
  • [4] Human-machine interactive streaming anomaly detection by online self-adaptive forest
    Qingyang LI
    Zhiwen YU
    Huang XU
    Bin GUO
    Frontiers of Computer Science, 2023, 17 (02) : 146 - 157
  • [5] Human-machine interactive streaming anomaly detection by online self-adaptive forest
    Li, Qingyang
    Yu, Zhiwen
    Xu, Huang
    Guo, Bin
    FRONTIERS OF COMPUTER SCIENCE, 2023, 17 (02)
  • [6] Human-machine interactive streaming anomaly detection by online self-adaptive forest
    Qingyang Li
    Zhiwen Yu
    Huang Xu
    Bin Guo
    Frontiers of Computer Science, 2023, 17
  • [7] A self-adaptive negative selection approach for anomaly detection
    Gonzalez, LJ
    Cannady, J
    CEC2004: PROCEEDINGS OF THE 2004 CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1 AND 2, 2004, : 1561 - 1568
  • [8] A Novel Self-Adaptive Clustering Algorithm for Dynamic Data
    Liu, Ming
    Lin, Lei
    Shan, Lili
    Sun, Chengjie
    NEURAL INFORMATION PROCESSING, ICONIP 2012, PT III, 2012, 7665 : 42 - 49
  • [9] ONLINE ANOMALY DETECTION IN VIDEOS BY CLUSTERING DYNAMIC EXEMPLARS
    Feng, Jie
    Zhang, Chao
    Hao, Pengwei
    2012 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP 2012), 2012, : 3097 - 3100