Unsupervised anomaly detection using an evolutionary extension of k-means algorithm

Wei Dar Lu, Issa Traoré · International Journal of Information and Computer Security · 2008

In this paper, we propose a new unsupervised anomaly detection framework for network intrusions. The framework consists of a new clustering algorithm named I-means and new anomalousness metrics named IP Weights. I-means is an evolutionary extension of k means algorithm that estimates automatically the number of clusters for a set of data. IP Weights allow the automatic conversion of regular packet features into a 3-dimensional numerical feature space. Online and offline evaluations show not only strong detection effectiveness, but also strong runtime efficiency, with response times falling within a few seconds ranges.

Read the paper · More papers on PaperTik