Network Anomaly Based Detection Using Multivariate Correlation Analysis Technique
T Anitha, Sanjay Kumar Bose, G Logeswari, N Maheswaran, S Vijayalakshmi, Dhamodharan Prabhu · 2023
In order to identify if network activity is an intrusion or normal, a multivariate correlation 1 analysis-based network anomaly-based intrusion detection system is proposed. The system identifies 2 activities, by taking input from the network traffic, and the input data is preprocessed and 3 transformed into a new set of data. A multivariate correlation model has been developed to identify 4 intrusions using Mahalanobis distance. The system's output is predicted to have a low false alarm 5 rate and a high accuracy rate. In the process of transformation, two types of transformation are done 6 one using the normal triangle area map generation using the base and height. The other one is based 7 on the cluster centroids area which uses a different approach for calculating the triangle area map 8 which uses the distance between the centroids and the input traffic data. After that, a multivariate 9 correlation model was developed based on the transformed data with the training samples and 10 the testing samples utilized to evaluate the performances of the multivariate model. The network 11 anomaly intrusion detection benchmark dataset, KDD cup 99, is taken for evaluation.