A Semi-supervised Clustering Algorithm for Network Intrusion Detection

Shengfeng Tian · Journal of the China Railway Society · 2010

Intrusion detection is one of the most important techniques in the domain of network security.This paper proposes a novel clustering algorithm,named k-cubes,for network anomaly detection.The network connection data are preprocessed with a grid-based algorithm.Then the grid cells are clustered with the proposed method.The number of clusters is automatically decided by dynamically merging and splitting of clusters.Also the semi-supervised version of k-cubes is presented.Detection rules are produced according to the clustering result.This method is suitable for processing large amount of high dimensional datasets with a lot of symbolic attribute values.It also limits the number of inputting parameters.Experimental results on the KDD99 intrusion detection datasets show that our algorithm achieves a detection rate of 95.82% with a false positive rate of 1.25%,and it detects 15 out of 17 new type of intrusions.

Read the paper · More papers on PaperTik