首页 | 本学科首页   官方微博 | 高级检索  
     

基于主成分分析禁忌搜索和决策树分类的异常流量检测方法
引用本文:冶晓隆,兰巨龙,郭通.基于主成分分析禁忌搜索和决策树分类的异常流量检测方法[J].计算机应用,2013,33(10):2846-2850.
作者姓名:冶晓隆  兰巨龙  郭通
作者单位:国家数字交换系统工程技术研究中心,郑州 450002
基金项目:国家科技支撑计划项目,国家863计划项
摘    要:真实网络流量包括大量特征属性,现有基于特征分析的异常流量检测方法无法满足高维特征分析要求。提出一种基于主成分分析和禁忌搜索(PCA-TS)的流量特征选择算法结合决策树分类的异常流量检测方法,通过PCA-TS对高维特征进行特征约减和近优特征子集选择,为决策树分类方法提供有效的低维特征属性,结合决策树分类精度和处理效率高的优点,采用半监督学习方式进行异常流量实时检测。实验表明,与传统异常检测方法相比,此方法具有更高的检测精度和更低的误检率,其检测性能受样本规模影响较小,且对未知异常可以进行有效检测

关 键 词:异常检测    决策树    特征选择    主成分分析    禁忌搜索
收稿时间:2013-03-22
修稿时间:2013-05-14

Network anomaly detection method based on principle component analysis and tabu search and decision tree classification
YE Xiaolong , LAN Julong , GUO Tong.Network anomaly detection method based on principle component analysis and tabu search and decision tree classification[J].journal of Computer Applications,2013,33(10):2846-2850.
Authors:YE Xiaolong  LAN Julong  GUO Tong
Affiliation:National Digital Switching System Engineering and Technological R&D Center, Zhengzhou Henan 450002, China
Abstract:Real network traffic contains mass of features, and the method of anomaly detection based on feature analysis is not suitable for high-dimensional features classification. A method based on Principal Component Analysis and tabu Tabu Search (PCA-TS) decision tree classification for anomaly detection was proposed. The method reduced high-dimensional features and selected optimal feature subset which was suitable for classification through PCA-TS algorithm, then the decision tree of higher detection rate and lower false rate was used for classification and detection based on semi-supervised learning. The experiment shows that the approach has higher detection accuracy and lower false rate compared with traditional anomaly detection method, and the detection performance is less affected by sample size and is suitable for real-time detection of unknown anomalies.
Keywords:anomaly detection  decision tree  feature selection  Principal Component Analysis (PCA)  Tabu Search (TS)
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号