作者: Aiguo Fei , Xiaoli Dong
DOI: 10.1109/ISIP.2010.96
关键词:
摘要: Intrusion detection systems (IDS) usually trigger a great number of alarm messages that frequently overwhelm their human operators. Hierarchically clustering technique is able to help IDS operators get meaningful overviews from the alarms. A dilemma encountered when clusters are generated. If obtained one by one, they cannot be prevented overlapping each other, which makes it quite likely mislead operator, if in batch, total must guessed before clustering, indicates possibly imprecise cluster or repeated running. In this paper, we propose GA (genetic algorithm)-based approach vary-lengthed chromosomes adopted instead fixed-lengthed chromosomes. The encoding scheme different numbers encoded into lengths addition, other genetic operations such as selection, crossover and mutation, discussed detail. Results several experiments encouraging, including newly proposed efficiently generate fitful high quality batch.