An Unsupervised Network Intrusion Detection Based on Anomaly Analysis

Jiang Zhong,Xiongbing Deng,Luosheng Wen,Yong Feng
DOI: https://doi.org/10.1109/icicta.2009.324
2009-01-01
Abstract:In this paper, an novel unsupervised intrusion detection method is presented, in which the anomalies was specified by choosing a reference measure mu which determines a density and a level value rho. in order to reveal the relationship between the distribution of connection feature data sets and the reference measure mu, we proposed a new method to design SVM classifier based on RBF core, and apply this algorithm to estimate density level set for the data set, through which the anomaly network connections have been detected. Experimental results on the real network data set showed that the new method is competitive with others in that the false alarm rate is kept low without many missed detections.
What problem does this paper attempt to address?