Invading Testing System Based on Clustering and HMM Distributed

Article Preview

Abstract:

In the invading testing, the testing of unknown is mainly accomplished by the abnormal testing. Traditional abnormal testing methods need to construct a normal behavior feature outline reference mode. When establish this mode, it is needed to have large amount of pure normal data set, and this data set usually is not easy to gain from the real network. Whats worse, the problem of too much error reports and leaking reports in the abnormal testing is pervasive. In order to overcome this shortage, this paper rises a abnormal testing method which is combine clustering analysis and HMM. This method doesnt need any training data set of manual marking; it can explore many different types of invading behaviors. The experimental results indicate that this method has better effect on the testing, which is of a higher testing rate and lower error report rate.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

456-461

Citation:

Online since:

October 2013

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2014 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

[1] L. Portnoy, E. Eskin and S.J. Stolfo. Intrusion Detection with Unlabeled Data Using Clustering. In Proceedings of ACM CSS Workshop on Data Mining Applied to Security (DMSA- 2001 . Phila delphia, PA: 2001. ).

Google Scholar

[2] Chentiemei, Huangdaoping etc, Applied Research of the Data preprocess of the Model Clustering. Computers and Applied Chemistry, 2003, 20(3) : 241-243.

Google Scholar

[3] KDD Cup 1999 DATASETS. http: /kdd. ics. uci. edu/databases/kddcup99/kddcup99. html. (1999).

Google Scholar

[4] Lazarevic, L. Ertoz, V. Kumar, A. Ozgur and J. Srivastava. A Comparative Study of Anomaly Detection Schemes in Network Intrusion Detection. In Proceedings of Third SIAM Conference on Data Mining, 2003, pp . 801-813.

DOI: 10.1137/1.9781611972733.3

Google Scholar