Detection and classification of anomaly intrusion using hierarchy clustering and SVM


Autoria(s): Tang, Chenghua; Xiang, Yang; Wang, Yu; Qian, Junyan; Qiang, Baohua
Data(s)

07/07/2016

Resumo

Anomaly detection as a kind of intrusion detection is good at detecting the unknown attacks or new attacks, and it has attracted much attention during recent years. In this paper, a new hierarchy anomaly intrusion detection model that combines the fuzzy c-means (FCM) based on genetic algorithm and SVM is proposed. During the process of detecting intrusion, the membership function and the fuzzy interval are applied to it, and the process is extended to soft classification from the previous hard classification. Then a fuzzy error correction sub interval is introduced, so when the detection result of a data instance belongs to this range, the data will be re-detected in order to improve the effectiveness of intrusion detection. Experimental results show that the proposed model can effectively detect the vast majority of network attack types, which provides a feasible solution for solving the problems of false alarm rate and detection rate in anomaly intrusion detection model.

Identificador

http://hdl.handle.net/10536/DRO/DU:30085317

Idioma(s)

eng

Publicador

John Wiley & Sons

Relação

http://dro.deakin.edu.au/eserv/DU:30085317/tang-detectionand-inpress-2016.pdf

http://www.dx.doi.org/10.1002/sec.1547

Direitos

2016, John Wiley & Sons

Palavras-Chave #anomaly intrusion detection #fuzzy c-means clustering #membership function #support vector machine
Tipo

Journal Article