An Outlier Cluster Detection Technique for Real-time Network Intrusion Detection Systems (실시간 네트워크 침입탐지 시스템을 위한 아웃라이어 클러스터 검출 기법)

  • Chang, Jae-Young;Park, Jong-Myoung;Kim, Han-Joon
    • Journal of Internet Computing and Services
    • v.8 no.6
    • pp.43-53
    • 2007
  • Intrusion detection system(IDS) has recently evolved while combining signature-based detection approach with anomaly detection approach. Although signature-based IDS tools have been commonly used by utilizing machine learning algorithms, they only detect network intrusions with already known patterns, Ideal IDS tools should always keep the signature database of your detection system up-to-date. The system needs to generate the signatures to detect new possible attacks while monitoring and analyzing incoming network data. In this paper, we propose a new outlier cluster detection algorithm with density (or influence) function, Our method assumes that an outlier is a kind of cluster with similar instances instead of a single object in the context of network intrusion, Through extensive experiments using KDD 1999 Cup Intrusion Detection dataset. we show that the proposed method outperform the conventional outlier detection method using Euclidean distance function, specially when attacks occurs frequently.

MCMC Particle Filter based Multiple Preceeding Vehicle Tracking System for Intelligent Vehicle (MCMC 기반 파티클 필터를 이용한 지능형 자동차의 다수 전방 차량 추적 시스템)

  • Choi, Baehoon;An, Jhonghyun;Cho, Minho;Kim, Euntai
    • Journal of the Korean Institute of Intelligent Systems
    • v.25 no.2
    • pp.186-190
    • 2015
  • Intelligent vehicle plans motion and navigate itself based on the surrounding environment perception. Hence, the precise environment recognition is an essential part of self-driving vehicle. There exist many vulnerable road users (e.g. vehicle, pedestrians) on vehicular driving environment, the vehicle must percept all the dynamic obstacles accurately for safety. In this paper, we propose an multiple vehicle tracking algorithm using microwave radar. Our proposed system includes various special features. First, exceptional radar measurement model for vehicle, concentrated on the corner, is described by mixture density network (MDN), and applied to particle filter weighting. Also, to conquer the curse of dimensionality of particle filter and estimate the time-varying number of multi-target states, reversible jump markov chain monte carlo (RJMCMC) is used to sampling step of the proposed algorithm. The robustness of the proposed algorithm is demonstrated through several computer simulations.

Performance Evaluation of One Class Classification to detect anomalies of NIDS (NIDS의 비정상 행위 탐지를 위한 단일 클래스 분류성능 평가)

  • Seo, Jae-Hyun
    • Journal of the Korea Convergence Society
    • v.9 no.11
    • pp.15-21
    • 2018
  • In this study, we try to detect anomalies on the network intrusion detection system by learning only one class. We use KDD CUP 1999 dataset, an intrusion detection dataset, which is used to evaluate classification performance. One class classification is one of unsupervised learning methods that classifies attack class by learning only normal class. When using unsupervised learning, it difficult to achieve relatively high classification efficiency because it does not use negative instances for learning. However, unsupervised learning has the advantage for classifying unlabeled data. In this study, we use one class classifiers based on support vector machines and density estimation to detect new unknown attacks. The test using the classifier based on density estimation has shown relatively better performance and has a detection rate of about 96% while maintaining a low FPR for the new attacks.

Adaptive Key-point Extraction Algorithm for Segmentation-based Lane Detection Network (세그멘테이션 기반 차선 인식 네트워크를 위한 적응형 키포인트 추출 알고리즘)

  • Sang-Hyeon Lee;Duksu Kim
    • Journal of the Korea Computer Graphics Society
    • /
    • /
    • pp.1-11
    • 2023
  • Deep-learning-based image segmentation is one of the most widely employed lane detection approaches, and it requires a post-process for extracting the key points on the lanes. A general approach for key-point extraction is using a fixed threshold defined by a user. However, finding the best threshold is a manual process requiring much effort, and the best one can differ depending on the target data set (or an image). We propose a novel key-point extraction algorithm that automatically adapts to the target image without any manual threshold setting. In our adaptive key-point extraction algorithm, we propose a line-level normalization method to distinguish the lane region from the background clearly. Then, we extract a representative key point for each lane at a line (row of an image) using a kernel density estimation. To check the benefits of our approach, we applied our method to two lane-detection data sets, including TuSimple and CULane. As a result, our method achieved up to 1.80%p and 17.27% better results than using a fixed threshold in the perspectives of accuracy and distance error between the ground truth key-point and the predicted point.

A Study on Exploring Urban Renewal Areas Using Spatial Density Analysis (공간 밀도분석을 이용한 재정비 대상지 탐색에 관한 연구)

  • Kijung Kim;Seungwook Go;Jinuk Sung
    • Land and Housing Review
    • /
    • /
    • pp.35-50
    • 2023
  • The purpose of this study is to identify areas in need of urban renewal by utilizing spatial data and analyzing their types and characteristics. For this, this research employed a kernel density function and K-means cluster analysis with spatial data, through which it sought ways to identify high-demand areas for urban renewal projects. The key findings and implications of the research are summarized as follows. Firstly, this research classified 587 target sites in Seoul based on development density (ratios) and an indicator for aged buildings. Approximately half of these areas were consistent with leading pilot project sites and Accelerated Integration Sites. Secondly, it was observed that residential environments in the designated leading pilot project sites, as decided by public sectors, were relatively poor compared to other areas. Lastly, the target areas for urban renewal were not clearly categorized through statistical analysis. Instead, it was found that categorization should be made depending on the requirements of each project.

Tectonic Link between NE China, Yellow Sea and Korean Peninsula, revealed by interpreting CHAMP-GRACE satellite Gravity Data and sea-surface measured gravity data (CHAMP-GRACE 인공위성 데이터와 해상 측정 중력 데이터에 나타난 황해안 지역의 남중국과 북중국판의 대륙 충돌대 위치)

  • Cho, Sung-Chan
    • 한국지구물리탐사학회:학술대회논문집
    • /
    • /
    • pp.9-14
    • 2005
  • For the understanding the locus of the Quinling-Dabie-Sulu continental collision's boundary and the underground structure of the sedimentray basin in the Yellow Sea, three dimensional density modelling is carrid out by using gravity dataset (Free Air Anomaly), which is measured by Tamhae 2, KIGAM in a period 2000 - 2002. The measured gravity anomaly in the investigations area is mainly responsed by depth distribution of the sedimentary basin. After comparing the sea-measured gravity data to CHAMP-GRACE satellite gravity data, I suggested that the high density model bodies extend mainly from the southern part of China to the middle-western part of the Korean Peninsula., which might be emplaced along the continental collision's boundary. The total volume of very low density bodies modified by modelling might be about $20000\;km^3$.

An Efficient Datapath Placement Algorithm to Minimize Track Density Using Spectral Method (스팩트럴 방법을 이용해 트랙 밀도를 최소화 할 수 있는 효과적인 데이터패스 배치 알고리즘)

  • Seong, Gwang-Su
    • Journal of the Institute of Electronics Engineers of Korea SD
    • /
    • /
    • pp.55-64
    • 2000
  • In this paper, we propose an efficient datapath placement algorithm to minimize track density. Here, we consider each datapath element as a cluster, and merge the most strongly connected two clusters to a new cluster until only one cluster remains. As nodes in the two clusters to be merged are already linearly ordered respectively, we can merge two clusters with connecting them. The proposed algorithm produces circular linear ordering by connecting starting point and end point of the final cluster, and n different linear ordering by cutting between two contiguous elements of the circular linear ordering. Among the n different linear ordering, the linear ordering to minimize track density is final solution. In this paper, we show and utilize that if two clusters are strongly connected in a graph, the inner product of the corresponding vectors mapped in d-dimensional space using spectral method is maximum. Compared with previous datapath placement algorithm GA/S $A^{[2]}$, the proposed algorithm gives similar results with much less computation time.

A Study on Efficient Technique of 3-D Terrain Modelling (3차원 지형모델링의 효율적 기법에 관한 연구)

  • 윤철규;신봉호;양승룡;엄재구
    • Journal of the Korean Society of Surveying, Geodesy, Photogrammetry and Cartography
    • /
    • /
    • pp.207-213
    • 1997
  • The purpose of this study is to aim at presenting efficient technique of 3-D Terrain Modelling through multilateral approach methods and to compare with raw data, using low-densed randomly located point data. The subject religion of this study are selected two sites and take into consideration for degree of freedom about low-densed randomly located point data. The result of this study by precision analysis of digital cartographic map-ping using low-densed randomly located point data bave shown that . First, making digital cartographic map, the technique of making it using low-desned randomly located point data by TIN-based results to good and fast run-time in A and B sites all together. Second, the visualization analysis results of digital cartographic map using TIN and GRID-based terrain modeling techniqus similar exacts A and B sites, but the terrain modeling techniqus by TIN-based are small data size than GRID-based with the data with the data size of saving with DXF files. Third, making digital catographic map using terrain modeling techniques by Grid-based, the standard errors of low-densed randomly located point data and interpolated data using gridding method have more good results by radial basis function interpolation techniques at A and B sites all together.

Density-Based Ramp Metering Method Considering Traffic of Freeway and Ramp on ITS (지능형 교통시스템에서 도시 고속도로와 램프의 교통량을 고려한 밀도 기반 램프 미터링 방법)

  • Jeon, Soobin;Jung, Inbum
    • KIISE Transactions on Computing Practices
    • /
    • /
    • pp.223-238
    • 2015
  • Ramp metering is the most effective and direct method to control a vehicle entering the freeway. This paper proposed the new density-based ramp metering method. Existing methods that use the flow data had low reliability data and can have various problems. Also, when the ramp metering was operated by freeway congestion, the additional congestion and over-capacity can occur in the ramp. To solve this problem with the existing method, the proposed method used the density and acceleration data of the freeway and considered the ramp status. The developed strategy was tested on Trunk Highway 62 west bound (TH-62 WB) in Minnesota Twin-City and compared with Stratified Zone Metering(SZM), which had been operating in the Twin-City freeway. To constitute the experiment environment, the VISSIM simulator was used. The Traffic Information and Condition Analysis System (TICAS) was developed to control the PTV VISSIM simulator. The experiment condition was set between 2:00 PM and 7:00 PM, Oct 5th, 2014 during severe traffic congestion. The simulation results showed that total travel time was reduced by 20% for SZM. Thus, we solved the problem of ramp congestion and over-capacity.