节点文献
改进的K-means算法在入侵检测中的应用
Application of Improved K-means Clustering Algorithm in Intrusion Detection
【摘要】 传统K-means聚类算法存在初始聚类中心选取敏感且需要预先设定聚类数等不足,导致入侵检测效率较低。为了提高入侵检测的准确性,提出一种改进的K-means算法。采用分离预处理记录属性的方法,在随机抽取的数据子集中基于密度距离生成初始聚类中心;利用类内最大相似度距离和类间最小相似度距离动态生成新类而无须事先确定K值。通过KDDCUP99数据集仿真实验表明,与传统的K-means聚类算法相比,改进的K-means算法有效提高了入侵检测的检测率,降低了误检率,缩短了检测时间。
【Abstract】 In the traditional K-means algorithm,the initial cluster center is selected sensitively and the number of clusters must be given in advice,which leads to low efficiency in intrusion detection.In order to improve detection accuracy,an improved K-means algorithm is proposed.The method of separation pretreatment record attributes is used.In randomly selected sub-data set,the initial cluster center is generated based on the density and distance.Use the largest similarity distance in classes and between classes to dynamically generate new classes without having to predetermine value of K.Simulation experiment is done in KDDCUP99.Compared with the traditional K-means clustering algorithm,the improved algorithm improves the detection rate,reduces the false detection rate and shortens the detection time.
【Key words】 intrusion detection; clustering algorithm; K-means algorithm;
- 【文献出处】 计算机技术与发展 ,Computer Technology and Development , 编辑部邮箱 ,2013年01期
- 【分类号】TP393.08
- 【被引频次】9
- 【下载频次】225