Application of improved k-means Algorithm in Intrusion Detection

Dong-wen ZHANG,Xue-jie ZHANG,Ji-qing QIU
DOI: https://doi.org/10.3969/j.issn.2095-6835.2010.18.005
2010-01-01
Abstract:In allusion to the disadvantage of k-means that need to obtain the number of clusters in advance,this paper addresses the improved k-means algorithm in terms of the dispersion measure of a cluster and dispersion measure among clusters on the condition that only the original data set is required.Firstly,the definition of dispersion measure of a cluster and dispersion measure among clusters are introduced.Then the definition and implementation process of the improved k-means algorithm is described carefully.Finally the experimental result on KDD CUP99 dataset shows that the improved algorithm has better detection results than the k-means algorithm in false alarm rate.
What problem does this paper attempt to address?