• DocumentCode
    1659285
  • Title

    Hierarchically Clustering IDS Alarms Using a GA with Vary-lengthed Chromosomes

  • Author

    Fei, Aiguo ; Dong, Xiaoli

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Beijing Univ. of Posts & Commun., Beijing, China
  • fYear
    2010
  • Firstpage
    172
  • Lastpage
    177
  • Abstract
    Intrusion detection systems (IDS) usually trigger a great number of alarm messages that frequently overwhelm their human operators. Hierarchically clustering technique is able to help IDS operators to get meaningful overviews from the great number of alarms. A dilemma is encountered when the clusters are generated. If the clusters are obtained one by one, they cannot be prevented from overlapping each other, which makes it quite likely to mislead the operator, if they are obtained in a batch, the total number of clusters must be guessed before clustering, which indicates possibly imprecise cluster number or repeated running. In this paper, we propose a GA (genetic algorithm)-based approach in which vary-lengthed chromosomes are adopted instead of fixed-lengthed chromosomes. The encoding scheme is that different numbers of clusters are encoded into different lengths of chromosomes. In addition, the other genetic operations such as selection, crossover and mutation, are discussed in detail. Results from several experiments are quite encouraging, including that the newly proposed approach is able to efficiently generate fitful number of clusters of high quality in a batch.
  • Keywords
    biology computing; cellular biophysics; genetic algorithms; pattern clustering; security of data; GA; encoding scheme; hierarchically clustering technique; intrusion detection systems; vary-lengthed chromosomes; Approximation algorithms; Biological cells; Clustering algorithms; Clustering methods; Equations; Gallium; Humans; genetic algorithm; hierarchical clustering; intrusion detection system; vary-lengthed chromosome;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Processing (ISIP), 2010 Third International Symposium on
  • Conference_Location
    Qingdao
  • Print_ISBN
    978-1-4244-8627-4
  • Type

    conf

  • DOI
    10.1109/ISIP.2010.96
  • Filename
    5669026