DocumentCode :
1684935
Title :
Optimizing Network Anomaly Detection Scheme Using Instance Selection Mechanism
Author :
Li, Yang ; Lu, Tian-Bo ; Guo, Li ; Tian, Zhi-hong ; Qi, Lin
Author_Institution :
Inst. of Comput. Technol., Chinese Acad. of Sci., Beijing, China
fYear :
2009
Firstpage :
1
Lastpage :
7
Abstract :
Network anomaly detection is a classically difficult research topic in intrusion detection. However, existing research has been solely focused on the detection algorithm. An important issue that has not been well studied so far is the selection of normal training data for network anomaly detection algorithm, which is highly related to the detection performance and computational complexity. Based on our previous proposed TCM-KNN (Transductive Confidence Machines for K-Nearest Neighbors) anomaly detection method, which can detect anomalies with high detection rate and low false positive rate, we develop an instance selection mechanism for TCM-KNN based on EFCM (Extended Fuzzy C-Means) clustering algorithm in this paper, aiming at limiting the size of training dataset, thus reducing the computational cost of TCM-KNN and boosting its detection performance. We report the experimental results over real network traffic. The results demonstrate the instance selection method presented in this paper is effective for TCM-KNN and thus optimizing it as an effectively lightweight network anomaly detection scheme.
Keywords :
computational complexity; fuzzy set theory; security of data; computational complexity; extended fuzzy C-means clustering algorithm; instance selection mechanism; intrusion detection; network anomaly detection scheme; transductive confidence machines for K-nearest neighbors; Boosting; Computational efficiency; Computers; Detection algorithms; Educational institutions; Intrusion detection; Mobile computing; Optimization methods; Telecommunication traffic; Testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2009. GLOBECOM 2009. IEEE
Conference_Location :
Honolulu, HI
ISSN :
1930-529X
Print_ISBN :
978-1-4244-4148-8
Type :
conf
DOI :
10.1109/GLOCOM.2009.5425547
Filename :
5425547
Link To Document :
بازگشت