Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems

被引:0
|
作者
Faour, Ahmad [1 ]
Leray, Philippe [1 ]
Eter, Bassam [2 ]
机构
[1] INSA Rouen, Lab LITIS, EA 4051, Rouen, France
[2] Lebanese Univ, Beirut, Lebanon
关键词
D O I
10.1007/978-1-4020-6270-4_58
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. This paper presents a new approach for handling intrusion detection alarms more efficiently. Self-Organizing Map (SOM) and Growing Hierarchical Self-Organizing Map (GHSOM) are used to discover interest patterns, signs of potential real attack scenarios aiming each machine in the network. GHSOM addresses two main limits of SOM which are caused, on the one hand, by the static architecture of this model, as well as, on the other hand, by the limited capabilities for the representation of hierarchical relations of the data. The experiments conducted on several logs extracted from the SNORT NIDS, confirm that the GHSOM can form an adaptive architecture, which grows in size and depth during its training process, thus to unfold the hierarchical structure of the analyzed logs of alerts
引用
收藏
页码:631 / 631
页数:1
相关论文
共 50 条
  • [1] Intrusion Detection Method Based on Improved Growing Hierarchical Self-Organizing Map
    张亚平
    布文秀
    苏畅
    王璐瑶
    许涵
    Transactions of Tianjin University , 2016, (04) : 334 - 338
  • [2] Intrusion Detection Method Based on Improved Growing Hierarchical Self-Organizing Map
    张亚平
    布文秀
    苏畅
    王璐瑶
    许涵
    Transactions of Tianjin University, 2016, 22 (04) : 334 - 338
  • [3] Intrusion detection method based on improved growing hierarchical self-organizing map
    Zhang Y.
    Bu W.
    Su C.
    Wang L.
    Xu H.
    Transactions of Tianjin University, 2016, 22 (04) : 334 - 338
  • [4] The growing hierarchical self-organizing map
    Dittenbach, M
    Merkl, D
    Rauber, A
    IJCNN 2000: PROCEEDINGS OF THE IEEE-INNS-ENNS INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, VOL VI, 2000, : 15 - 19
  • [5] Application of GHSOM (Growing Hierarchical Self-Organizing Maps) to Intrusion Detection Systems (IDS)
    Miguel De la Hoz, Eduardo
    Ortiz, Andres
    Ortega, Julio
    INGE CUC, 2012, 8 (01) : 117 - 147
  • [6] Gearbox failure detection using growing hierarchical self-organizing map
    Liao, Guanglan
    Shi, Tielin
    Tang, Zirong
    ADVANCES IN FRACTURE AND DAMAGE MECHANICS VI, 2007, 348-349 : 177 - +
  • [7] Growing Hierarchical Self-Organizing Map for Images Hierarchical Clustering
    Buczek, Bartlomiej M.
    Myszkowski, Pawel B.
    COMPUTATIONAL COLLECTIVE INTELLIGENCE: TECHNOLOGIES AND APPLICATIONS, PT I, 2011, 6922 : 52 - 61
  • [8] Recent advances with the Growing Hierarchical Self-Organizing Map
    Dittenbach, M
    Rauber, A
    Merkl, D
    ADVANCES IN SELF-ORGANISING MAPS, 2001, : 140 - 145
  • [9] The Prediction Approach with Growing Hierarchical Self-Organizing Map
    Huang, Shin-Ying
    Tsaih, Rua-Huan
    2012 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2012,
  • [10] Grey self-organizing map based intrusion detection
    王春东
    虞鹤峰
    王怀彬
    OptoelectronicsLetters, 2009, 5 (01) : 64 - 68