Skip to main content
Advertisement
Browse Subject Areas
?

Click through the PLOS taxonomy to find articles in your field.

For more information about PLOS Subject Areas, click here.

< Back to Article

Fig 1.

Two-Tier Feature Selection Procedure.

More »

Fig 1 Expand

Fig 2.

IDMEF alert format in an XML document.

More »

Fig 2 Expand

Table 1.

Attributes of an alert extracted from the XML document.

More »

Table 1 Expand

Table 2.

All features of DRAPA 2000 datasets.

More »

Table 2 Expand

Fig 3.

Information Gain algorithm.

More »

Fig 3 Expand

Table 3.

Feature ranking using IG on DMZ 1 DARPA 2000 dataset.

More »

Table 3 Expand

Table 4.

Feature ranking using IG on Inside 1 DARPA 2000 dataset.

More »

Table 4 Expand

Table 5.

Feature ranking using IG on DMZ 2 DARPA 2000 dataset.

More »

Table 5 Expand

Table 6.

Feature ranking using IG on Inside 2 DARPA 2000 dataset.

More »

Table 6 Expand

Fig 4.

Results of K-means with varying number of clusters.

More »

Fig 4 Expand

Fig 5.

Results of EM with varying number of clusters.

More »

Fig 5 Expand

Fig 6.

Results of Hierarchical with varying number of clusters.

More »

Fig 6 Expand

Table 7.

Summary on AR using K-means, EM and Hierarchical algorithm on all datasets before feature selection.

More »

Table 7 Expand

Fig 7.

Results of K-means after feature ranking.

More »

Fig 7 Expand

Fig 8.

Results of EM algorithm after feature e ranking.

More »

Fig 8 Expand

Fig 9.

Results of Hierarchical after feature ranking.

More »

Fig 9 Expand

Table 8.

Summary of clustering accuracy using K-means, EM and Hierarchical algorithm on all datasets after feature ranking.

More »

Table 8 Expand

Table 9.

The description of significant features of DARPA 2000 dataset.

More »

Table 9 Expand

Fig 10.

Results of K-means based on the seven selected features.

More »

Fig 10 Expand

Fig 11.

Results of EM based on the seven selected features.

More »

Fig 11 Expand

Fig 12.

Results of Hierarchical based on seven selected features.

More »

Fig 12 Expand

Table 10.

Summary on AR using K-means, FCM and EM algorithm on all datasets.

More »

Table 10 Expand

Table 11.

List of attack steps (clusters) discovered on all dataset.

More »

Table 11 Expand

Table 12.

Description of attack steps based on RealSecure Signatures Reference Guide Version 6.0 (Internet Security Systems.

More »

Table 12 Expand

Fig 13.

Comparison on accuracy performance of K-means in all datasets.

More »

Fig 13 Expand

Fig 14.

Comparison on accuracy performance of EM in all datasets.

More »

Fig 14 Expand

Table 13.

Performance comparison with other feature subsets.

More »

Table 13 Expand