Abstract
In this paper, a SOM-based anomaly intrusion detection system is proposed, which can contract high-dimension data to lower, meanwhile keeping the primary relationship between clustering and topology. During the experiment, the theory of SOM is used to train three SOMs on the layers of system, process and network. Although our experiment environment is simpler than the real one, the result shows that it has its reference value for us to build intelligent IDSs. Through the analysis of the monitoring results on the three layers from the hacking tools (NMAP, HYDRA), it is suggested that the approach of detecting and the parameters chosen be correct and effective.
Chapter PDF
Similar content being viewed by others
References
Ord, K.: Outliers in statistical data: V.barnett and t.lewis. International Journal of Forecasting 12(1), 175–176 (1996)
Kohonen, T.: Self-Organizing Maps. Springer Series in Information Sciences, vol. 30. Springer, Heidelberg (1995) (second extended edition 1997)
Zanero, S., Savaresi, S.M.: Unsupervised Learning Techniques for an Intrusion Detection System [C]. In: Proceedings of 2004 ACM Symposium on Applied Computing, Nicosia, Cyprus (2004)
Dangfeng, Z., Chunhui, H.: Research on Intrusion Detection Technique Based on Rapidly BP Learning Algorithm. Network Security Technology and Application (8), 36–37, 33 (2006)
Shengjun, W., Changzhen, H., Fei, J.: An Intrusion Detection Method Based on Improved BP Neural Network Algorithm. Computer Engineering 31(13), 154–155, 158 (2005)
Hagan, M.T., Dcmuch, H.B., Beale, M.: Neural Network Design. China Machine Press, Beijing (2002)
Kohonen, T., Hynninen, J., Kangas, J., Laaksonen, J.: SOM_PAK, The Self-Organizing Map Program Package, Version 3.1 (1995)
The Self-Organizing Map Program Package, http://www.cis.hut.fi/research/som_pak/
Author information
Authors and Affiliations
Editor information
Rights and permissions
Copyright information
© 2007 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Wang, Cd., Yu, Hf., Wang, Hb., Liu, K. (2007). SOM-Based Anomaly Intrusion Detection System. In: Kuo, TW., Sha, E., Guo, M., Yang, L.T., Shao, Z. (eds) Embedded and Ubiquitous Computing. EUC 2007. Lecture Notes in Computer Science, vol 4808. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-77092-3_31
Download citation
DOI: https://doi.org/10.1007/978-3-540-77092-3_31
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-77091-6
Online ISBN: 978-3-540-77092-3
eBook Packages: Computer ScienceComputer Science (R0)