Intrusion detection based on k-means clustering and OneR classification

Intrusion detection system (IDS) is used to detect various kinds of attacks in interconnected network. Many machine learning methods have also been introduced by researcher recently to obtain high accuracy and detection rate. Unfortunately, a potential drawback of all those methods is the rate of fa...

Full description

Saved in:
Bibliographic Details
Main Authors: Muda, Zaiton, Mohamed Yassin, Warusia, Sulaiman, Md. Nasir, Udzir, Nur Izura
Format: Conference or Workshop Item
Language:English
Published: IEEE 2011
Online Access:http://psasir.upm.edu.my/id/eprint/68939/1/Intrusion%20detection%20based%20on%20k-means%20clustering%20and%20OneR%20classification.pdf
http://psasir.upm.edu.my/id/eprint/68939/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Intrusion detection system (IDS) is used to detect various kinds of attacks in interconnected network. Many machine learning methods have also been introduced by researcher recently to obtain high accuracy and detection rate. Unfortunately, a potential drawback of all those methods is the rate of false alarm. However, our proposed approach shows better results, by combining clustering (to identify groups of similarly behaved samples, i.e. malicious and non-malicious activity) and classification techniques (to classify all data into correct class categories). The approach, KM+1R, combines the k-means clustering with the OneR classification technique. The KDD Cup '99 set is used as a simulation dataset. The result shows that our proposed approach achieve a better accuracy and detection rate, particularly in reducing the false alarm.