通信学报 ›› 2015, Vol. 36 ›› Issue (4): 19-26.doi: 10.11959/j.issn.1000-436x.2015127

• 学术论文 • 上一篇    下一篇

入侵检测中基于SVM的两级特征选择方法

武小年1,2,3,彭小金1,杨宇洋1,方堃   

  1. 1 桂林电子科技大学 信息与通信学院,广西 桂林 541004
    2 桂林电子科技大学 广西无线宽带通信与信息处理重点实验室,广西 桂林 541004
    3 桂林电子科技大学 广西信息科学实验中心,广西 桂林 541004
  • 出版日期:2015-04-25 发布日期:2015-04-15
  • 基金资助:
    广西自然科学基金资助项目;广西无线宽带通信与信号处理重点实验室2014年开放基金资助项目

Two-level feature selection method based on SVM for intrusion detection

Xiao-nian WU1,2,3,Xiao-jin PENG1,Yu-yang YANG1,Kun FANG   

  1. 1 School of Communication and Information,Guilin University of Electronic Technology,Guilin 541004,China
    2 Guangxi Wireless Broadband Communication and Signal Processing Key Laboratory,Guilin University of Electronic Technology,Guilin 541004
    3 Guangxi Experiment Center of Information Science,Guilin University of Electronic Technology,Guilin 541004,China
  • Online:2015-04-25 Published:2015-04-15
  • Supported by:
    The National Natural Science Foundation of Guangxi Province;The Key Laboratory Open Foud Preject of Broadband Wireless Communication and Signal Processing of Guangxi Province in 2014

摘要:

针对入侵检测中的特征优化选择问题,提出基于支持向量机的两级特征选择方法。该方法将基于检测率与误报率比值的特征评测值作为特征筛选的评价指标,先采用过滤模式中的Fisher分和信息增益分别过滤噪声和无关特征,降低特征维数;再基于筛选出来的交叉特征子集,采用封装模式中的序列后向搜索算法,结合支持向量机选取最优特征子集。仿真测试结果表明,采用该方法筛选出来的特征子集具有更好的分类性能,并有效降低了系统的建模时间和测试时间。

关键词: 入侵检测, 特征选择, 支持向量机, Fisher分, 序列后向搜索

Abstract:

To select optimized features for intrusion detection,a two-level feature selection method based on support vector machine was proposed.This method set an evaluation index named feature evaluation value for feature selection,which was the ratio of the detection rate and false alarm rate.Firstly,this method filtrated noise and irrelevant features to reduce the feature dimension respectively by Fisher score and information gain in the filtration mode.Then,a crossing feature subset was obtained based on the above two filtered feature sets.And combining support vector machine,the sequential backward selection algorithm in the wrapper mode was used to select the optimal feature subset from the crossing feature subset.The simulation test results show that,the better classification performance is obtained according to the selected optimal feature subset,and the modeling time and testing time of the system are reduced effectively.

Key words: intrusion detection, feature selection, support vector machine, Fisher score, sequential backward selection

No Suggested Reading articles found!