DocumentCode :
1659285
Title :
Hierarchically Clustering IDS Alarms Using a GA with Vary-lengthed Chromosomes
Author :
Fei, Aiguo ; Dong, Xiaoli
Author_Institution :
Sch. of Comput. Sci. & Technol., Beijing Univ. of Posts & Commun., Beijing, China
fYear :
2010
Firstpage :
172
Lastpage :
177
Abstract :
Intrusion detection systems (IDS) usually trigger a great number of alarm messages that frequently overwhelm their human operators. Hierarchically clustering technique is able to help IDS operators to get meaningful overviews from the great number of alarms. A dilemma is encountered when the clusters are generated. If the clusters are obtained one by one, they cannot be prevented from overlapping each other, which makes it quite likely to mislead the operator, if they are obtained in a batch, the total number of clusters must be guessed before clustering, which indicates possibly imprecise cluster number or repeated running. In this paper, we propose a GA (genetic algorithm)-based approach in which vary-lengthed chromosomes are adopted instead of fixed-lengthed chromosomes. The encoding scheme is that different numbers of clusters are encoded into different lengths of chromosomes. In addition, the other genetic operations such as selection, crossover and mutation, are discussed in detail. Results from several experiments are quite encouraging, including that the newly proposed approach is able to efficiently generate fitful number of clusters of high quality in a batch.
Keywords :
biology computing; cellular biophysics; genetic algorithms; pattern clustering; security of data; GA; encoding scheme; hierarchically clustering technique; intrusion detection systems; vary-lengthed chromosomes; Approximation algorithms; Biological cells; Clustering algorithms; Clustering methods; Equations; Gallium; Humans; genetic algorithm; hierarchical clustering; intrusion detection system; vary-lengthed chromosome;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Processing (ISIP), 2010 Third International Symposium on
Conference_Location :
Qingdao
Print_ISBN :
978-1-4244-8627-4
Type :
conf
DOI :
10.1109/ISIP.2010.96
Filename :
5669026
Link To Document :
بازگشت