A new data normalization method for unsupervised anomaly intrusion detection

被引:0
|
作者
Longzheng CAIJian CHENYun KETao CHENZhigang LI Engineering and Commerce CollegeSouthCentral University for NationalitiesWuhan China Guangdong Institute of Science and TechnologyZhuhai China [1 ,2 ,1 ,1 ,1 ,1 ,430065 ,2 ,519090 ]
机构
关键词
D O I
暂无
中图分类号
学科分类号
摘要
Unsupervised anomaly detection can detect attacks without the need for clean or labeled training data.This paper studies the application of clustering to unsupervised anomaly detection(ACUAD).Data records are mapped to a feature space.Anomalies are detected by determining which points lie in the sparse regions of the feature space.A critical element for this method to be effective is the definition of the distance function between data records.We propose a unified normalization distance framework for records with numeric and nominal features mixed data.A heuristic method that computes the distance for nominal features is proposed,taking advantage of an important characteristic of nominal features-their probability distribution.Then,robust methods are proposed for mapping numeric features and computing their distance,these being able to tolerate the impact of the value difference in scale and diversification among features,and outliers introduced by intrusions.Empirical experiments with the KDD 1999 dataset showed that ACUAD can detect intrusions with relatively low false alarm rates compared with other approaches.
引用
收藏
页码:778 / 784
页数:7
相关论文
共 50 条
  • [31] Intrusion Detection with Unsupervised Heterogeneous Ensembles using Cluster-based Normalization
    Ruoti, Scott
    Heidbrink, Scott
    O'Neill, Mark
    Gustafson, Eric
    Choe, Yung Ryn
    2017 IEEE 24TH INTERNATIONAL CONFERENCE ON WEB SERVICES (ICWS 2017), 2017, : 862 - 865
  • [32] Unsupervised Nonparametric Anomaly Detection: A Kernel Method
    Zou, Shaofeng
    Liang, Yingbin
    Poor, H. Vincent
    Shi, Xinghua
    2014 52ND ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2014, : 836 - 841
  • [33] A simple method for unsupervised anomaly detection: An application to Web time series data
    Yoshihara, Keisuke
    Takahashi, Kei
    PLOS ONE, 2022, 17 (01):
  • [34] Sequential Ensemble Method for Unsupervised Anomaly Detection
    Huy Van Nguyen
    Trung Thanh Nguyen
    Quang Uy Nguyen
    2017 9TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE 2017), 2017, : 71 - 76
  • [35] An Effective Unsupervised Network Anomaly Detection Method
    Bhuyan, Monowar H.
    Bhattacharyya, D. K.
    Kalita, J. K.
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 533 - 539
  • [36] Intrusion detection for high-speed railways based on unsupervised anomaly detection models
    Yao Wang
    Zujun Yu
    Liqiang Zhu
    Applied Intelligence, 2023, 53 : 8453 - 8466
  • [37] Intrusion detection for high-speed railways based on unsupervised anomaly detection models
    Wang, Yao
    Yu, Zujun
    Zhu, Liqiang
    APPLIED INTELLIGENCE, 2023, 53 (07) : 8453 - 8466
  • [38] A new similarity measure for the anomaly intrusion detection
    Belkhirat, Ahmed
    Bouras, Abdelghani
    Belkhir, Abdelkader
    NSS: 2009 3RD INTERNATIONAL CONFERENCE ON NETWORK AND SYSTEM SECURITY, 2009, : 431 - +
  • [39] HYPERSPECTRAL ANOMALY DETECTION WITH DATA SPHERING AND UNSUPERVISED TARGET DETECTION
    Chen, Shuhan
    Li, Xiaorun
    Zhao, Liaoying
    2022 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM (IGARSS 2022), 2022, : 1975 - 1978
  • [40] An Unsupervised Method For Intrusion Detection Using Spectral Clustering
    Gujral, Siddharth
    Ortiz, Estefan
    Syrmos, Vassilis L.
    IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE IN CYBER SECURITY, 2009, : 99 - 106