earticle

논문검색

An Improved Kernel Clustering Algorithm for Mixed-Type Data in Network Forensic

초록

영어

Clustering algorithm is a common analysis technology for network forensics, which, lacking of any prior knowledge, can effectively find out the invasions by analyzing the collected real-time communication data flowing through the network. This paper proposed an improved dynamic kernel clustering algorithm for mixed numeric and categorical network communication data. First, centroid prototype based on the mean and distribution centroid was put forward to represent the cluster center. Then by using Gaussian kernel function, the paper introduced a new dissimilarity measure between the data object and the centroid prototype in combination with the significance of different categorical values. On this basis, the objective function was defined, which took into account both the compact degree in a cluster and the discrete degree among the clusters. After that an improved kernel clustering algorithm was designed. In the process of clustering, centroid prototype and the value of the clustering parameter dynamically updated for a better description of the characteristics of clusters’ change. Finally, in order to verify the feasibility and effectiveness of the algorithm, the paper further applied it to network forensics, and the experimental results showed that the method could mine the intrusion behavior more accurately.

목차

Abstract
 1. Introduction
 2. Related Work
 3. Proposed Algorithm
  3.1. Notations
  3.2. Centroid Prototype
  3.3. Dissimilarity Measure
  3.4. Objective Function
  3.5. Improved Kernel Clustering aAgorithm
 4. Experiment and Result Analysis
  4.1. Dataset and Data Normalization
  4.2. Evaluation Method
  4.3. Experimental Results
 5. Conclusion and Future Work
 References

저자정보

  • Min Ren School of Information Science and Engineering, Shandong Normal University, Shandong, China, School of Mathematic and Quantitative Economics, Shandong University of Finance and Economics, Shandong, China
  • Peiyu Liu School of Information Science and Engineering, Shandong Normal University, Shandong, China, Shandong Provincial Key Laboratory for Distributed Computer Software Novel Technology, Shandong, China
  • Zhihao Wang School of Information Science and Engineering, Shandong Normal University, Shandong, China
  • Lin Lü School of Information Science and Engineering, Shandong Normal University, Shandong, China

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.