节点文献
数据流聚类算法在入侵检测中的应用
Application of data stream clustering algorithm in intrusion detection
【摘要】 处理数据流的能力成为入侵检测系统面临的挑战,针对这一现状提出DC-stream算法,该算法采用在线离线两阶段聚类,设计了一套缓冲式异常点处理机制,在保证数据流聚类效率和精度的同时,能够过滤噪音数据。实验结果证明,该算法能在海量的网络数据流中及时有效地发现入侵行为,并具有较强的抗干扰能力。
【Abstract】 The capacity of dealing with data streams has become a challenge for intrusion detection system.A DC-stream algorithm is proposed in view of this situation.Adopting both online and offline clustering,the DC-stream algorithm designs a buffer type anomaly detection mechanism,which can not only ensure the efficiency and accuracy of the data stream clustering,but also filter the noise data.The experimental result shows that the algorithm can detect intrusion behaviors in the mass network data stream timely and effectively,and has strong antiinterference ability.
【关键词】 入侵检测;
核心微簇;
缓冲微簇;
聚类纯度;
【Key words】 intrusion detection; core micro cluster; buffer micro cluster; cluster purity;
【Key words】 intrusion detection; core micro cluster; buffer micro cluster; cluster purity;
【基金】 河北省科技计划项目(No.10213559)
- 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2012年20期
- 【分类号】TP393.08
- 【被引频次】8
- 【下载频次】108