A Repeated Sampling and Clustering Method for Intrusion Detection

MWITONDI, Kassim and ZARGARI, Shahrzad (2017). A Repeated Sampling and Clustering Method for Intrusion Detection. In: STAHLBOCK, Robert, ABOU-NASR, Mahmoud and WEISS, Gary M., (eds.) Proceedings of the 13th International Conference on Data Mining (DMIN '17). CSREA Press, 91-96.

[img] PDF (Las Vegas 2017)
Las-Vegas-2017-DMI3482.pdf - Published Version
Restricted to Repository staff only
Available under License All rights reserved.

Download (1MB)
Official URL: http://csce.ucmss.com/cr/books/2017/LFS/CSREA2017/...

Abstract

Various tools, methods and techniques have been developed in recent years to deal with intrusion detection and ensure network security. However, despite all these efforts, gaps remain, apparently due to insufficient data sources on attacks on which to train and test intrusion detection algorithms. We propose a data-flow adaptive method for intrusion detection based on searching through high-dimensional dataset for naturally arising structures. The algorithm is trained on a subset of 82332 observations on 25 numeric variables and one cyber-attack label and tested on another large subset of similar structure. Its novelty derives from iterative estimation of cluster centroids, variability and proportions based on repeated sampling. Data visualisation and numerical results provide a clear separation of a set of variables associated with two types of attacks. We highlight the algorithm’s potential extensions – its allurement to predictive modelling and adaptation to other dimensional-reduction techniques.

Item Type: Book Section
Research Institute, Centre or Group: Cultural Communication and Computing Research Institute > Communication and Computing Research Centre
Related URLs:
Depositing User: Kassim Mwitondi
Date Deposited: 18 Aug 2017 08:50
Last Modified: 18 Aug 2017 09:00
URI: http://shura.shu.ac.uk/id/eprint/16537

Actions (login required)

View Item View Item

Downloads

Downloads per month over past year

View more statistics