节点文献

一种基于聚类的异常入侵检测方法

A Clustering Method for Anomaly Intrusion Detection

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 刘凤珠龚勋

【Author】 LIU Feng-zhu,GONG Xun(Department of Computer Science,Sichuan University,Chengdu,Sichuan 610065,China)

【机构】 四川大学计算机学院

【摘要】 传统的K均值聚类算法采用欧式距离计算样本间的相似度,由于未考虑不同样本属性对于衡量样本间距离区分度的重要性,导致相似度计算不准确,聚类性能较差。提出了一种改进的K均值聚类算法,通过计算每个属性相对于聚类类别的信息增益率,将信息增益率作为属性权重计算加权欧式距离,使对类别区分度贡献较大的属性拥有较大的权重,以提高样本间的相似性度量的准确性。在经典的入侵检测数据集UCI KDD CUP上的实验结果证明,与传统的基于K均值的入侵检测方法相比,此方法能够有效地提高检测准确率。

【Abstract】 Euclidean distance is used to calculate similarity between samples by traditional K-means clustering algorithm.The importance of different attributes is not considered.As a result,the sample’s distance measurement is not accurate;the quality of clustering is bad.To solve the problem,an improved k-means clustering algorithm was proposed.By calculating every attribute’s information gain ratio with respect to clustering class,take the information gain ratio as weight to calculate Euclidean distance.In this way,the attributes which more contributing to classify get more weight,the measurement between samples is more accurate.By experiments on classic UCI KDD CUP intrusion detection dataset,the result shows that,comparing with traditional k-means intrusion detection method,the method proposed by this paper can effectively improve detection accuracy.

【基金】 国家自然科学基金(61173159)
  • 【文献出处】 计算机安全 ,Computer Security , 编辑部邮箱 ,2013年08期
  • 【分类号】TP393.08
  • 【被引频次】10
  • 【下载频次】117
节点文献中: 

本文链接的文献网络图示:

本文的引文网络