An Intrusion Detection Research Based on Spectral Clustering

A spectral clustering intrusion detection approach is presented in this paper. The basic idea of the approach is to compute the similarities between the training data points, then to construct the affinity matrix, and to get the clusters according the main eigenvector of this affinity matrix. With the classified data instances, anomaly data clusters can be easily identified by normal cluster ratio. The benefits of the approach lie in that it is accurate in clustering and it needn 't labeled training data sets. Using the data sets of KDD99, the experiment result shows that this approach can detect intrusions efficiently in the real network connections.

[1]  Yair Weiss,et al.  Segmentation using eigenvectors: a unifying view , 1999, Proceedings of the Seventh IEEE International Conference on Computer Vision.

[2]  Santosh S. Vempala,et al.  On clusterings-good, bad and spectral , 2000, Proceedings 41st Annual Symposium on Foundations of Computer Science.

[3]  Eleazar Eskin,et al.  A GEOMETRIC FRAMEWORK FOR UNSUPERVISED ANOMALY DETECTION: DETECTING INTRUSIONS IN UNLABELED DATA , 2002 .

[4]  Zhang Huan-guo An Unsupervised Clustering-Based Intrusion Detection Method , 2003 .

[5]  Wang Li-na,et al.  Research and implementation of unsupervised clustering-based intrusion detection , 2008, Wuhan University Journal of Natural Sciences.

[6]  Santosh S. Vempala,et al.  On clusterings: Good, bad and spectral , 2004, JACM.

[7]  James Cannady,et al.  Artificial Neural Networks for Misuse Detection , 1998 .

[8]  Leonid Portnoy,et al.  Intrusion detection with unlabeled data using clustering , 2000 .

[9]  Michael Schatz,et al.  Learning Program Behavior Profiles for Intrusion Detection , 1999, Workshop on Intrusion Detection and Network Monitoring.

[10]  Risto Miikkulainen,et al.  Intrusion Detection with Neural Networks , 1997, NIPS.

[11]  Susan M. Bridges,et al.  Mining fuzzy association rules and fuzzy frequency episodes for intrusion detection , 2000, Int. J. Intell. Syst..

[12]  Jitendra Malik,et al.  Normalized cuts and image segmentation , 1997, Proceedings of IEEE Computer Society Conference on Computer Vision and Pattern Recognition.