Analyzing Intrusion Alerts Based on Kernel Neural-Gas Clustering

XIAO Yun,HAN Chong-zhao,ZHENG Qing-hua,ZAN Xin
DOI: https://doi.org/10.3321/j.issn:1001-506x.2006.09.039
2006-01-01
Abstract:The unsupervised kernel neural-gas clustering method was applied to analyze intrusion alerts.The kernel neural-gas clustering method was improved for its high runtime,so the process of learning speeds up while its astringency is not affected.The improved kernel neural-gas clustering method was used to cluster the true alert data,and the frequency distributing figures of each neural as best matching unit are obtained.Based on these figures,the discriminant rules are gained to distinguish false positive alerts from true alerts.The experimental data is the alerts produced by Snort,a kind of network intrusion detection system,monitoring the attack and normal data in experimental environment.The testing results confirm the good performance of the proposed method: false positive alerts are reduced by 81% with sliding window of 10,at the cost of false negative alerts increased by 6%.
What problem does this paper attempt to address?