节点文献

基于分箱统计的FCM算法及其在网络入侵检测中的应用

FCM Algorithm Based on Box-FCM Statistics and its Application in Network Intrusion Detection

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 傅涛孙文静孙亚民

【Author】 FU Tao1 SUN Wen-Jing2 SUN Ya-Min1(College of Computer,Nanjing University of Science & Technology , Nanjing 210094)1 (Nanjing Audit University , Nanjing 210029) 2

【机构】 南京理工大学计算机学院南京审计学院南京理工大学计算机学院 南京210094南京210029南京210094

【摘要】 使用KDDCup99网络入侵检测数据,对传统的FCM(Fuzzy C-Means)算法进行实验,发现该聚类算法在进行聚类划分和孤立点判断时,存在划分粗略性现象。针对该问题,本文提出使用分箱统计的FCM方法来划分和描述数据集的分布。与原有算法相比,不需要频繁更新聚类中心,同时耗时问题也得到较好的改善。文章最后将特征匹配与基于分箱的FCM算法相结合,协同分析网络连接数据记录。实验结果证明,这种协同检测方法的检测率有明显提高,实时性好,能较好地发现新的攻击类型,便于检测知识库的更新。

【Abstract】 This paper carried experiments on the traditional FCM (Fuzzy C Means) algorithm by using KDDCup99 intrusion-detection data of network and found that when clustering division and isolated-point judgments were carried out, phenomenon of rough division was existed in this algorithm. To this question the paper presented that classifying and describing the distribution of data sets by using of the statistics box-FCM methods. Compared with the original algorithm it didn’t need to update the clustering center frequently and could resolve time-consuming problems effectively. Finally this paper combined feature matching with box-FCM algorithm so that network connection data records could be coordinated analyzed. Experiments proved that the detection efficiency of this real-time method was improved noticeably and some new intrusion ways could be detected to update the knowledge base.

【基金】 江苏省产业技术研究与开发基金,苏发改高技发[2006]1106号
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2008年04期
  • 【分类号】TP393.08
  • 【被引频次】11
  • 【下载频次】161
节点文献中: 

本文链接的文献网络图示:

本文的引文网络