Authors G.V. Karaychev
Month, Year 11, 2009 @en
Index UDC 004.956:519.237.8
Abstract The paper provides information on high productivity unsupervised anomaly detection based on adaptive construction of system profile. Initial connection records are transformed using principal component analysis and clustered by adaptive grid-based algorithm. Evaluation (KDD CUP"99 data set) demonstrates that effectiveness of suggested approach is comparable with other anomaly analysis methods.

Keywords Network security; anomaly analysis; principal component analysis; clusterization; adaptive grid-based algorithm; ROC analysis.
