A hybrid network intrusion detection framework based on random forests and weighted k-means

被引:93
|
作者
Elbasiony, Reda M. [1 ]
Sallam, Elsayed A. [1 ]
Eltobely, Tarek E. [1 ]
Fahmy, Mahmoud M. [1 ]
机构
[1] Tanta Univ, Fac Engn, Tanta, Gharbia, Egypt
关键词
Computer network security; Data mining; Intrusion detection; Random forests; k-Means;
D O I
10.1016/j.asej.2013.01.003
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Many current NIDSs are rule-based systems, which are very difficult in encoding rules, and cannot detect novel intrusions. Therefore, a hybrid detection framework that depends on data mining classification and clustering techniques is proposed. In misuse detection, random forests classification algorithm is used to build intrusion patterns automatically from a training dataset, and then matches network connections to these intrusion patterns to detect network intrusions. In anomaly detection, the k-means clustering algorithm is used to detect novel intrusions by clustering the network connections' data to collect the most of intrusions together in one or more clusters. In the proposed hybrid framework, the anomaly part is improved by replacing the k-means algorithm with another one called weighted k-means algorithm, moreover, it uses a proposed method in choosing the anomalous clusters by injecting known attacks into uncertain connections data. Our approaches are evaluated over the Knowledge Discovery and Data Mining (KDD'99) datasets. (C) 2013 Ain Shams University. Production and hosting by Elsevier B.V. All rights reserved.
引用
收藏
页码:753 / 762
页数:10
相关论文
共 50 条
  • [1] A HYBRID FRAMEWORK BASED ON NEURAL NETWORK MLP AND K-MEANS CLUSTERING FOR INTRUSION DETECTION SYSTEM
    Lisehroodi, Mazyar Mohammadi
    Muda, Zaiton
    Yassin, Warusia
    COMPUTING & INFORMATICS, 4TH INTERNATIONAL CONFERENCE, 2013, 2013, : 305 - +
  • [2] Hybrid Weighted K-Means Clustering and Artificial Neural Network for an Anomaly-Based Network Intrusion Detection System
    Samrin, Rafath
    Vasumathi, Devara
    JOURNAL OF INTELLIGENT SYSTEMS, 2018, 27 (02) : 135 - 147
  • [3] Hybrid Intrusion Detection System using K-means and Random Tree Algorithms
    Aung, Yi Yi
    Min, Myat Myat
    2018 19TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD), 2018, : 218 - 223
  • [4] A Hybrid Intrusion Detection System Based on Scalable K-Means plus Random Forest and Deep Learning
    Liu, Chao
    Gu, Zhaojun
    Wang, Jialiang
    IEEE ACCESS, 2021, 9 : 75729 - 75740
  • [5] Hybrid Intrusion Detection Method Based on K-means and CNN for Smart Home
    Liu, Kaijian
    Fan, Zhen
    Liu, Meiqin
    Zhang, Senlin
    2018 IEEE 8TH ANNUAL INTERNATIONAL CONFERENCE ON CYBER TECHNOLOGY IN AUTOMATION, CONTROL, AND INTELLIGENT SYSTEMS (IEEE-CYBER), 2018, : 312 - 317
  • [6] A Network Intrusion Detection Model Based on K-means Algorithm and Information Entropy
    Meng, Gao
    Dan, Li
    Ni-Hong, Wang
    Li-Chen, Liu
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (06): : 285 - 294
  • [7] A K-means algorithm based on characteristics of density applied to network intrusion detection
    Xu, Jing
    Han, Dezhi
    Li, Kuan-Ching
    Jiang, Hai
    COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2020, 17 (02) : 665 - 687
  • [8] Intrusion Detection Based on MinMax K-means Clustering
    Eslamnezhad, Mohsen
    Varjani, Ali Yazdian
    2014 7TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2014, : 804 - 808
  • [9] A hybrid network intrusion detection technique using random forests
    Zhang, Jiong
    Zulkernine, Mohammad
    FIRST INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2006, : 262 - +
  • [10] A hybrid intrusion detection system with K-means and CNN+LSTM
    Lv, Haifeng
    Ding, Yong
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2024, 11 (06):