Intrusion Detection System Based on Gaussian Mixture Model Using Hadoop Framework
Zhijian Wang, Yanqin Zhu · 2017
The traditional intrusion detection system is to match the rule base and network packets one by one, and then detect the abnormal behavior. When the amount of network data increases, the detection efficiency is significantly reduced, and even faces a huge challenge that it cannot be immediately detected. Hadoop framework is a great choice in dealing with big data. Hadoop can not only store huge data, but also speed up the data processing. In this paper, we propose a distributed Gaussian mixture model based on Hadoop framework. We use a two-step MapReduce process to implement this algorithm. And then, we deploy the Hadoop framework in the virtual machine to verify the efficiency of the algorithm. The results show that, this algorithm has a good performance in reducing the consumption of time.