loading
Papers

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Denis Hock 1 ; Martin Kappes 1 and Bogdan Ghita 2

Affiliations: 1 Frankfurt University of Applied Sciences, Germany ; 2 Plymouth University, United Kingdom

ISBN: 978-989-758-196-0

Keyword(s): Computer Networks, Network Anomaly Detection, Clustering.

Related Ontology Subjects/Areas/Topics: Information and Systems Security ; Intrusion Detection & Prevention ; Network Security ; Wireless Network Security

Abstract: While Anomaly Detection is commonly accepted as an appropriate technique to uncover yet unknown network misuse patterns and malware, detection rates are often diminished by, e.g., unpredictable user behavior, new applications and concept changes. In this paper, we propose and evaluate the benefits of using clustering methods for data preprocessing in Anomaly Detection in order to improve detection rates even in the presence of such events. We study our pre-clustering approach for different features such as IP addresses, traffic characteristics and application layer protocols. Our results obtained by analyzing detection rates for real network traffic with actual intrusions indicates that our approach does indeed significantly improve detection rates and, moreover, is practically feasible.

PDF ImageFull Text

Download
CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 100.24.122.228

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Hock, D.; Kappes, M. and Ghita, B. (2016). A Pre-clustering Method To Improve Anomaly Detection.In Proceedings of the 13th International Joint Conference on e-Business and Telecommunications - Volume 4: SECRYPT, (ICETE 2016) ISBN 978-989-758-196-0, pages 391-396. DOI: 10.5220/0005953003910396

@conference{secrypt16,
author={Denis Hock. and Martin Kappes. and Bogdan Ghita.},
title={A Pre-clustering Method To Improve Anomaly Detection},
booktitle={Proceedings of the 13th International Joint Conference on e-Business and Telecommunications - Volume 4: SECRYPT, (ICETE 2016)},
year={2016},
pages={391-396},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0005953003910396},
isbn={978-989-758-196-0},
}

TY - CONF

JO - Proceedings of the 13th International Joint Conference on e-Business and Telecommunications - Volume 4: SECRYPT, (ICETE 2016)
TI - A Pre-clustering Method To Improve Anomaly Detection
SN - 978-989-758-196-0
AU - Hock, D.
AU - Kappes, M.
AU - Ghita, B.
PY - 2016
SP - 391
EP - 396
DO - 10.5220/0005953003910396

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.