Title :
Anomaly Detection with Self-Organizing Maps and Effects of Principal Component Analysis on Feature Vectors
Author :
Kiziloren, Tevfik ; Germen, Emin
Author_Institution :
BAUM Comput. Res. & Applic. Center, Anadolu Univ., Eskisehir, Turkey
Abstract :
Network anomaly detection is the problem of scrutinizing of unauthorized use of computer systems over a network. In literature there are plenty different methods produced for detecting network anomalies and the process of anomaly detection is one of the major topics that computer science is working on. In this work, a classification method is introduced to perform this discrimination based on self organizing network (SOM) classifier. Also, rather than proving well-known abilities of SOM on classification, our main concern in this work was investigating effects of principal component analysis on quality of feature vectors. In order to signify the power of success, KDD Cup 1999 dataset is used. KDD Cup dataset is a common benchmark for evaluation of intrusion detection techniques. The dataset consists of several components and here, it is used `10% corrected´ test dataset. Since the feature vectors obtained from the dataset have prominent impact of success on the method, the usage of PCA and a method of choosing reliable components are introduced. At the end it is mentioned that the success of decision by the proposed method has been improved. In order to clarify this improvement, a detailed comparison of changing number of principal components on the success of decision mechanism is given.
Keywords :
authorisation; computer network security; principal component analysis; self-organising feature maps; vectors; KDD Cup dataset; classification method; feature vector; intrusion detection technique; network anomaly detection; principal component analysis; self organizing network classifier; self-organizing maps; Application software; Computer applications; Computer networks; Computer science; Data mining; Data security; Hidden Markov models; Intrusion detection; Principal component analysis; Self organizing feature maps; DoS; PCA; SOM;
Conference_Titel :
Natural Computation, 2009. ICNC '09. Fifth International Conference on
Conference_Location :
Tianjin
Print_ISBN :
978-0-7695-3736-8
DOI :
10.1109/ICNC.2009.652