Fast Regularized Least Squares and k-means Clustering Method for Intrusion Detection Systems
Parisa Movahedi, Paavo Nevalainen, Markus Viljanen, Tapio Pahikkala · 2015
Intrusion detection systems are intended for reliable, accurate and efficient detection of attacks in a large networked system. Machine learning methods have shown promising results in terms of accuracy but one disadvantage they share is the high computational cost of training and prediction phase when applied to intrusion detection. Recently some methods have been introduced to increase this efficiency. Kernel based methods are one of the most popular methods in the literature, and extending them with approximation techniques we describe in this paper has a huge impact on minimizing the computational time of the Intrusion Detection System (IDS). This paper proposes using optimized Regularized Least Square (RLS) classification combined with k-means clustering. Standard techniques are used in choosing the optimal RLS predictor parameters. The optimization leads to fewer basis vectors which improves the prediction speed of the IDS. Our algorithm evaluated on the KDD99 benchmark IDS dataset demonstrates considerable improvements in the training and prediction times of the intrusion detection while maintaining the accuracy.