Normalized Method of Intrusion Detection Data Based on Information Theory in Big Data Environment

Yong SONG,Zhiping CAI
DOI: https://doi.org/10.14188/j.1671-8836.2018.02.004
2018-01-01
Abstract:In the era of big data,intrusion detection is widely used as an important means of network security.Different characteristics of network intrusion detection data have different dimension and dimension units.In order to eliminate the influence of dimension between feature attributes,normalization is usually done before data analysis.Most of the normalized processing only considers the distribution of the attribute value itself without objectively evaluating its influence on the category information or other characteristic attributes.Aiming at this problem,this paper proposes a method of normalizing network intrusion detection data based on information theory.For the continuous feature attributes,the joint information gain is taken as an evaluation method of interval segmentation,and normalization is done according to the proportion of the interval category.For the discrete feature attributes,normalization is done according to the proportion of the conditional entropy.Simulation results using NSL-KDD dataset show that the method can not only improve the convergence of learning algorithms,but also improve the detection rate of classification model and reduce the false alarm rate of classification model.
What problem does this paper attempt to address?