Research Article

A Modified Hybrid Method Based on PSO, GA, and K-Means for Network Anomaly Detection

Table 1

Network data identification type.

Identification typeMeaningSpecific classification identification

NormalNormal recordNormal
DoSDenial of service attackBack, land, Neptune, pod, smurf, teardrop
ProbeMonitoring and other detection activitiesIpsweep, nmap, portsweep, Satan
R2LUnauthorized access from remote machineftp_write, guess_passwd, imap, multihop, phf, spy, warezclient, warezmaster
U2RUnauthorized access to root authority by ordinary usersbuffer_overflow, loadmodule, perl, rootkit