@inproceedings{e846252683ad44b0b092c3c35cc7af04,
title = "Attribute normalization in network intrusion detection",
abstract = "Anomaly intrusion detection is an important issue in computer network security. As a step of data preprocessing, attribute normalization is essential to detection performance. However, many anomaly detection methods do not normalize attributes before training and detection. Few methods consider to normalize the attributes but the question of which normalization method is more effective still remains. In this paper, we introduce four different schemes of attribute normalization to preprocess the data for anomaly intrusion detection. Three methods, k-NN, PCA as well as SVM, are then employed on the normalized data for comparison of the detection results. KDD Cup 1999 data are used to evaluate the normalization schemes and the detection methods. The systematical evaluation results show that the process of attribute normalization improves a lot the detection performance. The statistical normalization scheme is the best choice for detection if the data set is large.",
author = "Wei Wang and Xiangliang Zhang and Sylvain Gombault and Knapskog, {Svein J.}",
year = "2009",
doi = "10.1109/I-SPAN.2009.49",
language = "English (US)",
isbn = "9780769539089",
series = "I-SPAN 2009 - The 10th International Symposium on Pervasive Systems, Algorithms, and Networks",
publisher = "IEEE Computer Society",
pages = "448--453",
booktitle = "I-SPAN 2009 - The 10th International Symposium on Pervasive Systems, Algorithms, and Networks",
address = "United States",
note = "10th International Symposium on Pervasive Systems, Algorithms, and Networks, I-SPAN 2009 ; Conference date: 14-12-2009 Through 16-12-2009",
}