首页 | 本学科首页   官方微博 | 高级检索  
     

基于特征分组聚类的异常入侵检测系统研究
引用本文:何发镁,马慧珍,王旭仁,冯安然. 基于特征分组聚类的异常入侵检测系统研究[J]. 计算机工程, 2020, 46(4): 123-128,134
作者姓名:何发镁  马慧珍  王旭仁  冯安然
作者单位:北京理工大学图书馆,北京100081;中国科学院信息工程研究所中国科学院网络测评技术重点实验室,北京100093;中国科学院信息工程研究所中国科学院网络测评技术重点实验室,北京100093;首都师范大学信息工程学院,北京100048
摘    要:利用网络连接数据可以按照连接的基本特征、内容特征、网络流量特征和主机流量特征进行分组的特点,基于K-means算法,提出一种按照特征分组进行聚类的方法,以高效实现特征约简和数据降维.通过调整聚类参数保留特征分组内的差异信息,使用决策树C4.5算法对降维后的数据进行入侵分类处理.实验结果表明,该方法能够使kddcup99数据集的聚类特征数由41个降为4个,且对网络连接数据的总检测率为99.73%,误检率为0,其中正常网络连接和刺探攻击Probe的检测率均为100%.

关 键 词:入侵检测  网络数据  K-MEANS算法  决策树  数据降维

Research on Anomaly Intrusion Detection System Based on Feature Grouping Clustering
HE Famei,MA Huizhen,WANG Xuren,FENG Anran. Research on Anomaly Intrusion Detection System Based on Feature Grouping Clustering[J]. Computer Engineering, 2020, 46(4): 123-128,134
Authors:HE Famei  MA Huizhen  WANG Xuren  FENG Anran
Affiliation:(Library,Beijing Institute of Technology,Beijing 100081,China;Key Laboratory of Network Assessment Technology,Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China;Information Engineering College,Capital Normal University,Beijing 100048,China)
Abstract:The network connection data can execute feature grouping according to the basic features of connection,the content features,the network traffic features and the host features.Taking advantage of this characteristic,this paper proposes a K-means based clustering method according to the grouping of features,so as to effectively achieve feature reduction and data dimensionality reduction.The differential information within the feature groups are retained by adjusting clustering parameters,and the decision tree C4.5 algorithm is used for intrusion classification of the data after dimensionality reduction.Experimental results show that the proposed method can reduce the number of clustering features of kddcup99 dataset from 41 to 4.The overall detection rate on network connection data is 99.73%,the false detection rate is 0 and the detection rates of normal network connection and Probe attack are both 100%.
Keywords:intrusion detection  network data  K-means algorithm  decision tree  data dimensionality reduction
本文献已被 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号