Intrusion Detection Classifier Based On Self-Organizing Ant Colony Networks Clustering

Yong Feng,Jiang Zhong,Chun-Xiao Ye,Zhong-Yang Xiong,Zhong-Fu Wu
2006-01-01
Abstract:Due to the fact that it is more and more improbable to a system administrator to recognize and manually intervene to stop an attack, there is an increasing recognition that ID systems should have a lot to earn on following its basic principles on the behavior of complex natural systems, namely in what refers to self-organization, allowing for a real distributed and collective perception of this phenomena. A clustering model based on Self-Organizing Ant Colony Networks (CSOACN) is systematically proposed for intrusion detection system. The basic idea of CSOACN is to produce the cluster by our enhanced ant colony clustering algorithm. With the classified data instances, the detection classifier can be established. And then the detection classifier can be used in real intrusion detection. Instead of using the linear segmentation function of the CSI model and the complex probability conversion function of the LF model, here we propose to use a simple nonlinear probability conversion function in our enhanced ant colony clustering and can help to solve linearly inseparable problems of CSI and slow convergence speed of LF. Using a set of benchmark data from 1998 DARPA, we demonstrate that the efficiency and accuracy of CSOACN-based classifier.
What problem does this paper attempt to address?