Computer Engineering and Applications ›› 2009, Vol. 45 ›› Issue (29): 111-113.DOI: 10.3778/j.issn.1002-8331.2009.29.033

• 网络、通信、安全 • Previous Articles     Next Articles

Data stream intrusion detection algorithm based on dynamic classifier ensemble

CHI Qian1,ZHAO Nan2   

  1. 1.College of Mechanical and Electronic Engineering,Northwest A & F University,Xi’an 712100,China
    2.Research Institute 25,Institute of Space II,Beijing 100871,China
  • Received:2009-07-28 Revised:2009-09-23 Online:2009-10-11 Published:2009-10-11
  • Contact: CHI Qian

分类器动态集成的入侵数据流检测算法

迟 茜1,赵 楠2   

  1. 1.西北农林科技大学 机电学院,西安 712100
    2.航天第二研究院 25所,北京 100871
  • 通讯作者: 迟 茜

Abstract: Intrusion data stream is characterized by high speed updating and concept drifting.Static classifier ensemble cannot cope with data distribution in the whole feature space,which results in low detection accuracy.In this paper,a dynamic classifier ensemble based intrusion detection algorithm is presented,which sets the weight of each base classifier dynamically,detecting concept drifting and updating classifier ensemble by interval estimation.Experiment result shows that the proposed algorithm outperforms majority voting and weighted majority voting,two static classifier ensemble methods,and that it has high detection accuracy on real-life intrusion detection dataset.

Key words: intrusion detection, data streams, dynamic ensemble, concept drifting

摘要: 入侵数据流具有快速更新以及概念漂移的特点,静态集成分类器无法及时反映整个空间的数据分布,入侵检测正确率不高,对此,文中提出了一种单分类器动态集成的入侵检测方法,该方法动态分配各分类器权值并用区间估计检查概念漂移并更新分类器。实验结果表明,在处理超平面构造的数据流上,分类效果优于多数投票、加权投票两种静态分类方法,在真实入侵实数据集上有高检测率。

关键词: 入侵检测, 数据流, 动态集成, 概念漂移

CLC Number: