节点文献
基于分箱统计的FCM算法及其在网络入侵检测中的应用
FCM Algorithm Based on Box-FCM Statistics and its Application in Network Intrusion Detection
【摘要】 使用KDDCup99网络入侵检测数据,对传统的FCM(Fuzzy C-Means)算法进行实验,发现该聚类算法在进行聚类划分和孤立点判断时,存在划分粗略性现象。针对该问题,本文提出使用分箱统计的FCM方法来划分和描述数据集的分布。与原有算法相比,不需要频繁更新聚类中心,同时耗时问题也得到较好的改善。文章最后将特征匹配与基于分箱的FCM算法相结合,协同分析网络连接数据记录。实验结果证明,这种协同检测方法的检测率有明显提高,实时性好,能较好地发现新的攻击类型,便于检测知识库的更新。
【Abstract】 This paper carried experiments on the traditional FCM (Fuzzy C Means) algorithm by using KDDCup99 intrusion-detection data of network and found that when clustering division and isolated-point judgments were carried out, phenomenon of rough division was existed in this algorithm. To this question the paper presented that classifying and describing the distribution of data sets by using of the statistics box-FCM methods. Compared with the original algorithm it didn’t need to update the clustering center frequently and could resolve time-consuming problems effectively. Finally this paper combined feature matching with box-FCM algorithm so that network connection data records could be coordinated analyzed. Experiments proved that the detection efficiency of this real-time method was improved noticeably and some new intrusion ways could be detected to update the knowledge base.
【Key words】 FCM algorithm; Based on statistical binning; Statistics; Feature matching; Coordinated analysis;
- 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2008年04期
- 【分类号】TP393.08
- 【被引频次】11
- 【下载频次】161