An efficient hybrid SVDD/clustering approach for anomaly-based intrusion detection
Tayeb Kenaza, Khadidja Bennaceur, Abdenour Labed · 2018
A hybrid solution is proposed in this paper to enhance the quality of anomaly detection systems using Supports Vectors Data Description (SVDD). The SVDD aims to characterize the dataset of a single target class. In the case of Intrusion Detection Systems (IDS) the SVDD model is trained using only the class of normal user behavior. Indeed, the learning step consists of finding the hypersphere that encloses the entire scatter of the training set. Notice that the resulting model have to be optimal, i.e. a hypersphere with a minimal radius. This assumes implicitly that the scatter is spherical which is not always true. This paper deals with the general case where the scatter may have a random shape. In this case, some voids may occur in the hypersphere which mainly causes a distortion of the data description, and consequently reduces the accuracy of the detection. We propose a set of improvements that helps removing internal and external voids to enhance the detection accuracy. Experimental results show the effectiveness of our proposals to enhance the accuracy of the SVDD-based anomaly detection, especially the hybridization between SVDD and the clustering.