Title
False positive elimination in intrusion detection based on clustering
Abstract
In order to solve the problem of high false positive in network intrusion detection systems, we adopted clustering algorithms, the K-means algorithm and the Fuzzy C Mean (FCM) algorithm, to identify false alerts, to reduce invalid alerts and to purify alerts for a better analysis. In this paper, we first introduced typical clustering algorithms, including the partition clustering, the hierarchical clustering, the density and grid clustering, and the fuzzy clustering, and then analyzed their feasibilities in security data processing. Furthermore, we introduced an intrusion detection framework, and tested the validity and feasibility of false positive elimination in intrusion detection. The process steps of false positive elimination were clearly described, and additionally, two typical clustering algorithms, the K-means algorithm and the FCM algorithm, were implemented for false alerts identification and filtration. Also, we defined three evaluation indexes: the elimination rate, the false elimination rate and the miss elimination rate. Accordingly, we used DARPA 2000 LLDOS1.0 dataset for our experiments, and adopted Snort as our intrusion detection system. Eventually, the results showed that the method proposed by us has a satisfactory validity and feasibility in false positive elimination, and the clustering algorithms we adopted can achieve a high elimination rate.
Year
DOI
Venue
2015
10.1109/FSKD.2015.7381996
2015 12th International Conference on Fuzzy Systems and Knowledge Discovery (FSKD)
Keywords
Field
DocType
Intrusion Detection,False Positive Elimination,K-means,FCM
Data mining,Fuzzy clustering,CURE data clustering algorithm,Computer science,Artificial intelligence,Cluster analysis,Intrusion detection system,Hierarchical clustering,Canopy clustering algorithm,k-means clustering,Correlation clustering,Pattern recognition,Machine learning
Conference
Citations 
PageRank 
References 
0
0.34
12
Authors
4
Name
Order
Citations
PageRank
liang hu1348.17
Taihui Li200.34
Nannan Xie300.34
Jiejun Hu401.01