模糊P均值聚类(FCM)的算法是在硬P均值算法(HCM)发展而来的,虽然改进了硬产均值算法的聚类效果,但带来了时间复杂度的增加.提出了一种基于协议分析分类的并行入侵检测模型,根据协议分析将大的数据集进行分类。构成不同的数据集,先对各个数据集进行FCM聚类。然后对每个FCM聚类的结果再次进行FCM聚类.构成并行处理系统.采用协议分析技术结合高速数据包捕捉、协议解析等技术来进行分布式入侵检测,可以提高入侵检测的速度.
Fuzzy c-means(FCM) clusters extends from Hard c-means algorithm, which has improved the clusters' efficiency of HCM, but it increases Time Complexity. This paper presents a Parallel Clustering Intrusion Detection Model based on Protocol Analysis. A large data set is partitioned into several different sets. These different sets are carried on FCM clustering. Then their results are reused to implement FCM clustering. They constitute parallel system. Distributed intrusion detection is implemented using the combination of protocol analysis and high-speed data capture, which enhances intrusion detection velocity.