• using clustering to improve the knn-based classifiers for online anomaly network traffic identification

    نویسندگان :
    جزئیات بیشتر مقاله
    • تاریخ ارائه: 1392/07/24
    • تاریخ انتشار در تی پی بین: 1392/07/24
    • تعداد بازدید: 990
    • تعداد پرسش و پاسخ ها: 0
    • شماره تماس دبیرخانه رویداد: -
     this paper proposes a method to identify flooding attacks in real-time, based on anomaly detection by genetic weighted knn (k-nearest-neighbor) classifiers. a genetic algorithm is used to train an optimal weight vector for features; meanwhile, an unsupervised clustering algorithm is applied to reduce the number of instances in the sampling dataset, in order to shorten training and execution time, as well as to promote the system’s overall accuracy. more precisely, instances in the sampling dataset are replaced by less, but more significant, centroids of clusters. according to the proposed method, a system is implemented and evaluated by numerous denial-of-service (dos) attacks. with an embedded weighted knn classifier, the proposed system could identify a dos attack from network traffic within a very short time; moreover, the experimental results show that the proposed system could achieve 95.8654% in overall accuracy in the case of 2-fold cross-validation, and 96.25% in overall accuracy for all known attack evaluations. that is, the proposed system possesses both effectiveness and efficiency. effectiveness is measured by overall accuracy, including detection rate and false alarm rate, and efficiency is measured by the response time during an attack.

سوال خود را در مورد این مقاله مطرح نمایید :

با انتخاب دکمه ثبت پرسش، موافقت خود را با قوانین انتشار محتوا در وبسایت تی پی بین اعلام می کنم
مقالات جدیدترین رویدادها
مقالات جدیدترین ژورنال ها