A novel model of IDS based on automatic clustering number determination
Jing Zhong, Jiang Xiong, Xiaofeng Chen, Hongjuan Wu · 2010 Sixth International Conference on Natural Computation · 2010
To address the problem of how to pre-define a clustering number in Fuzzy C-means algorithm(FCM), a clustering algorithm, F-CMSVM, (Fuzzy C-means and Support Vector Machine algorithm), is proposed so as to determine the clustering number in an automatic way. Above all, the data set is classified into two clusters by FCM. Then, support vector machine (SVM) with a fuzzy membership function is to testify whether the data set can be further classified. Thus, the result of clusters can be obtained by repeating the computation process. Because affiliating matrix, obtained by the introduction of SVM into FCM, is defined to be the fuzzy membership function, each different input data sample can have different penalty value, and the separating hyper-plane is optimized. F-CMSVM is an unsupervised algorithm in which it is neither needed to label training data set nor specify clustering number. As shown from our simulation experiment over networks connection records from KDD CUP 1999 data set, F-CMSVM has efficient performance in clustering number optimization and intrusion detection.