PCA mix‐based Hotelling's T2 multivariate control charts for intrusion detection system

Abstract Most of the data, which is in the field of network intrusion detection, have the characteristics of a mixture of high‐dimensional datasets of continuous and categorical variables. It easily leads the traditional multivariate control chart to get the error detection results. Hotelling's...

Full description

Saved in:
Bibliographic Details
Main Authors: Mo Shaohui, Gulanbaier Tuerhong, Mairidan Wushouer, Tuergen Yibulayin
Format: Article
Language:English
Published: Wiley 2022-05-01
Series:IET Information Security
Subjects:
Online Access:https://doi.org/10.1049/ise2.12051
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Abstract Most of the data, which is in the field of network intrusion detection, have the characteristics of a mixture of high‐dimensional datasets of continuous and categorical variables. It easily leads the traditional multivariate control chart to get the error detection results. Hotelling's T2 multivariate control charts based on Principal Component Analysis mix (PCA mix) with bootstrap control limit were proposed, and applied to the network intrusion detection system. It was compared with the conventional Hotelling's T2 control chart based on PCA and the performance of the control limits obtained with the bootstrap method was compared to the ones calculated using the most commonly used kernel density estimation. The experimental results revealed that the proposed method had better performance in intrusion detection than its counterparts.
ISSN:1751-8709
1751-8717