DocumentCode
3650471
Title
Network traffic anomaly detection using clustering techniques and performance comparison
Author
Duo Liu;Chung-Horng Lung;Ioannis Lambadaris;Nabil Seddigh
Author_Institution
Department of Systems and Computer Eng. Carleton University, Ottawa, Ontario, Canada
fYear
2013
Firstpage
1
Lastpage
4
Abstract
Real-time network traffic anomaly detection is crucial for the confidentiality, integrity, and security of network information. Machine learning approaches are widely used to distinguish traffic flow outliers based on different anomalies with unique statistical characteristics. K-means clustering and Gaussian Mixture Model (GMM) are effective clustering techniques with many variations and easy to implement. Fuzzy clustering is more flexible than hard clustering and is practical for intrusion detection because of the natural treatment of data using fuzzy clustering. Fuzzy c-means clustering (FCM) is an iteratively optimal algorithm normally based on the least square method to partition data sets, which has high computational overhead. This paper proposes modifications to the objective function and the distance function that reduce the computational complexity of FCM while keeping clustering accurate. A combination of FCM clustering GMM, and feature transformation methods are proposed and a comparison of the related testing results and clustering methods is presented.
Keywords
"Principal component analysis","Covariance matrices","Clustering algorithms","Telecommunication traffic","Gaussian mixture model","Partitioning algorithms"
Publisher
ieee
Conference_Titel
Electrical and Computer Engineering (CCECE), 2013 26th Annual IEEE Canadian Conference on
ISSN
0840-7789
Print_ISBN
978-1-4799-0031-2
Type
conf
DOI
10.1109/CCECE.2013.6567739
Filename
6567739
Link To Document