A hybrid network intrusion detection framework based on random forests and weighted k-means

被引:93
|
作者
Elbasiony, Reda M. [1 ]
Sallam, Elsayed A. [1 ]
Eltobely, Tarek E. [1 ]
Fahmy, Mahmoud M. [1 ]
机构
[1] Tanta Univ, Fac Engn, Tanta, Gharbia, Egypt
关键词
Computer network security; Data mining; Intrusion detection; Random forests; k-Means;
D O I
10.1016/j.asej.2013.01.003
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Many current NIDSs are rule-based systems, which are very difficult in encoding rules, and cannot detect novel intrusions. Therefore, a hybrid detection framework that depends on data mining classification and clustering techniques is proposed. In misuse detection, random forests classification algorithm is used to build intrusion patterns automatically from a training dataset, and then matches network connections to these intrusion patterns to detect network intrusions. In anomaly detection, the k-means clustering algorithm is used to detect novel intrusions by clustering the network connections' data to collect the most of intrusions together in one or more clusters. In the proposed hybrid framework, the anomaly part is improved by replacing the k-means algorithm with another one called weighted k-means algorithm, moreover, it uses a proposed method in choosing the anomalous clusters by injecting known attacks into uncertain connections data. Our approaches are evaluated over the Knowledge Discovery and Data Mining (KDD'99) datasets. (C) 2013 Ain Shams University. Production and hosting by Elsevier B.V. All rights reserved.
引用
收藏
页码:753 / 762
页数:10
相关论文
共 50 条
  • [21] Intrusion detection based on MLP neural networks and K-means algorithm
    Zheng, HY
    Ni, L
    Xiao, D
    ADVANCES IN NEURAL NETWORKS - ISNN 2005, PT 3, PROCEEDINGS, 2005, 3498 : 434 - 438
  • [22] Intrusion Detection based on K-Means Clustering and Naive Bayes Classification
    Muda, Z.
    Yassin, W.
    Sulaiman, M. N.
    Udzir, N. I.
    2011 7TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY IN ASIA (CITA 11), 2011,
  • [23] An Anomaly Intrusion Detection Method Based on Improved K-means of Cloud
    Zhao, Xinlong
    Zhang, Weishi
    PROCEEDINGS OF 2016 SIXTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2016), 2016, : 284 - 288
  • [24] Network intrusion detection using hybrid binary PSO and random forests algorithm
    Malik, Arif Jamal
    Shahzad, Waseem
    Khan, Farrukh Aslam
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (16) : 2646 - 2660
  • [25] A Modified Hybrid Method Based on PSO, GA, and K-Means for Network Anomaly Detection
    Yuan, Yuan
    Li, Yuangang
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2022, 2022
  • [26] Improved K-means clustering algorithm in intrusion detection
    Xiao, ShiSong
    Li, XiaoXu
    Liu, XueJiao
    2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 2, 2008, : 771 - 775
  • [27] Intrusion Detection with K-Means Clustering and OneR Classification
    Muda, Z.
    Yassin, W.
    Sulaiman, M. N.
    Udzir, N. I.
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2012, 7 (06): : 347 - 354
  • [28] Research on the Application of Improved K-Means in Intrusion Detection
    Wei, Mingjun
    Xia, Lichun
    Su, Jingjing
    INFORMATION COMPUTING AND APPLICATIONS, PT I, 2011, 243 : 673 - +
  • [29] Hybrid Intrusion Detection System using K-means and Classification and Regression Trees Algorithms
    Aung, Yi Yi
    Min, Myat Myat
    2018 IEEE/ACIS 16TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT AND APPLICATION (SERA), 2018, : 195 - 199
  • [30] K-Random Forests: a K-means style algorithm for Random Forest clustering
    Bicego, Manuele
    2019 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2019,