Skip to main navigation Skip to search Skip to main content

Method of anomaly detection based on fusion principal components match

  • Yan Heng Liu*
  • , Lei Sun
  • , Da Xin Tian
  • , Jing Wu
  • , Feng Hua Zhang
  • *Corresponding author for this work
  • College of Computer Science and Technology
  • Jilin University
  • Jilin Oilfield Vocation Education Center

Research output: Contribution to journalArticlepeer-review

Abstract

According to the expansion of data storage, a method of anomaly detection based on Fusion Principal Component Match (FPCM) is presented. First, the isolated points in the sub-node data are removed and the stability of the principal component analysis is enhanced by clustering. Then the clustering center is transmitted to a center node, which can reduce the traffic of data between nodes and achieve the fusion principal components. The normal behavior model established by the conversion matrix of the principal component cluster centers can embody the characteristics of the overall data. Finally, the decision tree method is used to accelerate the matching speed. Experiment results show that the FPCM method can maintain a high detection rate of DOS, an overall detection rate of 97% is obtained; meanwhile, the false positives is controlled below 10%. The detection rate of this method is equal to that of the existing methods.

Original languageEnglish
Pages (from-to)1314-1320
Number of pages7
JournalJilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition)
Volume39
Issue number5
StatePublished - Sep 2009
Externally publishedYes

Keywords

  • Clustering
  • Computer system organization
  • Decision trees
  • Intrusion detection
  • Principal component analysis

Fingerprint

Dive into the research topics of 'Method of anomaly detection based on fusion principal components match'. Together they form a unique fingerprint.

Cite this