In order to overcome the shortcomings in traditional anomaly intrusion detection methods, such as low detection rate and high false alarm rate, this paper proposes an intrusion detection method based on wavelet kernel Least Square Support Vector Machine (LS-SVM). As a new machine learning method, SVM has been used in Intrusion Detection System (IDS) recently and achieved certain effects. While the commonly used kernel functions of SVM such as RBF kernel and Gauss kernel are non-orthogonal, whose detection capacity and speed are unsatisfactory for complex non-linear system in IDS. LS-SVM is an evolution of classical SVM. It looks for the solution by solving linear equations instead of a convex quadratic programming in classical SVM. Wavelet kernel function has the capability of approximately orthogonal and multi-scale analysis, and has better classification and generalizing ability. Experiment on KDD CUP1999 shows our method could raise the accuracy of detection and decrease the false alarm rate.
Haihua GaoXingyu WangHuihua Yang