Anomaly Detection Model Based on Hybrid Classifiers

王飞,徐本连,钱玉文,戴跃伟,王执铨
DOI: https://doi.org/10.16182/j.cnki.joss.2012.04.037
2012-01-01
Abstract:In view of the disadvantage,of an anomaly detection which can not provide more useful information about the unknown intrusions,an anomaly detection model based on hybrid SVM/SOM was proposed.At first,support vector machine(SVM) was used to detect anomalous connections,and then the detected anomalies were as input of the clustering module to get more information.The clustering module consisted of self-organizing map(SOM) algorithm and information acquisition algorithm.Through the method of acquire information about the detected anomalies,more valuable information about the unknown intrusions could be obtained.Finally,the kddcup99 data sets were used for simulation.The experimental results show that the detection model has a better detection efficiency and low false alarm rate,and the model for getting information of unknown intrusions is valid.
What problem does this paper attempt to address?