Font Size: a A A

Clustering Techniques In Research And Application In Network Intrusion Detection

Posted on:2011-11-06Degree:MasterType:Thesis
Country:ChinaCandidate:W X ZhangFull Text:PDF
GTID:2208330332477170Subject:Software engineering
Abstract/Summary:
With the continuous development of computer networks, information has become a major trend of human development. Thus, network security will inevitably become an important issue. People demand on its system security is increasing as well. Intrusion detection systems (IDS) are one of the requirements. It is an active real-time tracking system to check the attacks and internal misuse, and timely respond. Based on the data analysis, intrusion detection systems can be divided into misuse detection systems and anomaly detection system, while on the basis of the audit data sources, they can be divided into host-based Intrusion Detection System (HIDS) and network-based Intrusion Detection System (NIDS).This thesis focuses on the intrusion detection system, describes its research development, makes an analysis of the characteristics, structure and classification of intrusion detection systems, analyzes the development direction, and its frequently used research method. Also, it further discusses the application of the clustering technology in the Intrusion Detection System, and makes an assessment to the system performance. The new points to this thesis lie in the following:1. The amount of the network data is increasingly surging, which makes the sharp increase in the audit data. The difficulty to achieve intrusion detection is the representative system model extracted from the massive audit data. This thesis has designed a data mining-based adaptive intrusion detection system which can collect data from its own system and can automatically generate the test data by training these models to achieve the complete automation on data collection, model building and the process of the testing. When the detection of environmental changes, intrusion detection systems do not need to make great changes, and when new types of attacks or new normal behavior patterns emerge, intrusion detection system can better recognize it and automatically improve its knowledge base.2. In the process of the systematic training data, if the data is not clean enough, it will lead to some abnormal data and its variants which will be regarded as normal data. As a matter of the fact, it is not quite easy to collect a full set of clean training data. This system commonly applies to K-means clustering algorithm. Based on K-means algorithm, it is improved a lot, which makes it easier to the identification and training of abnormal data set containing the data to automatically determine the optimal parameters of class distinctions. This method reduces the data set of training requirements and can better connect the data from the network to detect new intrusions. ]...
Keywords/Search Tags:intrusion detection systems, data mining, clustering techniques, K-means algorithm
Related items