This work summarizes our research on the topic of the application of unsupervised learning algorithms to the problem of intrusion detection, and in particular our main research results in network intrusion detection. We proposed a novel, two tier architecture for network intrusion detection, capable of clustering packet payloads and correlating anomalies in the packet stream. We show the experiments we conducted on such architecture, we give performance results, and we compare our achievements with other comparable existing systems.
No takes yet. Share an insight, caveat, or question.
Zanero et al. (2008) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: