A new data normalization method for unsupervised anomaly intrusion detection

来源 :Journal of Zhejiang University-Science C(Computers & Electro | 被引量 : 0次 | 上传用户:moxihuanyu
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Unsupervised anomaly detection can detect attacks without the need for clean or labeled training data.This paper studies the application of clustering to unsupervised anomaly detection(ACUAD).Data records are mapped to a feature space.Anomalies are detected by determining which points lie in the sparse regions of the feature space.A critical element for this method to be effective is the definition of the distance function between data records.We propose a unified normalization distance framework for records with numeric and nominal features mixed data.A heuristic method that computes the distance for nominal features is proposed,taking advantage of an important characteristic of nominal features-their probability distribution.Then,robust methods are proposed for mapping numeric features and computing their distance,these being able to tolerate the impact of the value difference in scale and diversification among features,and outliers introduced by intrusions.Empirical experiments with the KDD 1999 dataset showed that ACUAD can detect intrusions with relatively low false alarm rates compared with other approaches. Unsupervised anomaly detection can detect detect without the need for clean or labeled training data. This paper studies the application of clustering to unsupervised anomaly detection (ACUAD). Data records are mapped to a feature space. sparse regions of the feature space. A critical element for this method to be effective is the definition of the distance function between data records. We propose a unified normalization distance framework for records with numeric and nominal features mixed data. A heuristic method that computes the distance for nominal features is proposed, taking advantage of an important characteristic of nominal features-their probability distribution.Then, robust methods are proposed for mapping numeric features and computing their distance, these being able to tolerate the impact of the value difference in scale and diversification among features, and outliers introduced by intrusions.Empirical experiments with the KDD 1999 dataset showed that ACUAD can detect intrusions with relatively low false alarm rates compared with other approaches.
其他文献
陈云是中国社会主义经济建设的开创者和奠基人之一。他在长期领导全国财政经济工作中,洞悉全局,抓住要害,及时拿出解决问题的有效办法。本文运用实证分析法,从生活环境、传统
本文对云南学校肺结核疫情与控制对策进行了探讨。中国是世界上22个结核病高负担国家之一,云南是中国结核病流行严重的省份之一,肺结核又是长期肆虐广大青少年身体健康的主要疾病之一。2004-2006年学校传染病总发病数居各职业人群的第二位(仅次于农民),2006-2007年学校突发公共卫生事件中的发病数居全国第一位。学校传染病前五种疾病(病毒性肝炎、肺结核、痢疾、伤寒和副伤寒、麻疹)的发病总数,分别占全
随着质子泵抑制剂的应用,消化性溃疡(peptic ulcer,PU)多数在6~8周能治愈,但诸多因素可影响到PU的复发。笔者在2002年3月至2005年10月对治愈后的316例PU患者进行随访调查,观察
急性上消化道出血(AUG IH)是严重威胁患者生命健康的临床危重症,多以消化性溃疡(PU)、肝硬化(HC)、急性胃粘膜病变(AGML)等为主要病因〔1〕。有研究表明,这些疾病中幽门螺旋
目的了解福州市流动人群的麻疹和风疹抗体水平,为麻疹和风疹的预防控制工作提供依据。方法采用酶联免疫吸附试验检测随机调查的0~44岁477名流动人群麻疹和风疹IgG抗体。结果
本书是一部国际知名的经典经济学教科书。不仅在英语世界获得了广泛的认可,同时被翻译成日文、俄文、保加利亚文、匈牙利文等多种语言畅销全世界,在经济转型国家引起巨大反响
目的观察阿托伐他汀对实验性自身免疫性脑脊髓炎(EAE)的治疗作用并初步探讨其治疗机制。方法将大鼠分为正常组、模型组、阿托伐他汀组,每组6只。正常组不做任何处理;以豚鼠脑
中国是世界上结核病负担最重的国家之一,其病例总数位居第二〔1〕。据估计,80%的结核病例是农村病人,肺结核是引起农村地区因病致贫的主要疾病之一〔2〕。如何有效发现结核病
随着步兵重要性的提高,出现了一系列增强步兵作战效能的改进方案,包括通过未来士兵系统把步兵及其嵌入到网络中。但万变不离其宗,突击步枪仍然是未来士兵不可或缺的进攻性武
摘 要:对宜昌市中小学生心理健康状况及心理健康教育需求的调查表明,中小学生在人际关系方面存在不同程度问题,学习态度普遍较为积极,但有部分学生由于压力过大引起了躯体化反应,“学业不佳”排在心理困扰之首,学生对心理健康教育需求很大。因此,要建立适应中小学生需要的心理健康教育体系,通过多种途径改善学生方方面面的人际关系,加强学习心理辅导,引导学生正确看待学习过程和学习结果。  关键词:中小学生;心理健