Anomaly Detection Enhanced Classification in Computer Intrusion Detection

作者: Mike Fugate , James R. Gattiker

DOI: 10.1007/3-540-45665-1_15

关键词: One-class classificationData miningAnomaly (natural sciences)Intrusion detection systemArtificial intelligencePattern recognitionComputer scienceMahalanobis distancePattern recognition (psychology)Anomaly detectionBenchmark (computing)Support vector machine

摘要: This paper describes experiences and results applying Support Vector Machine (SVM) to a Computer Intrusion Detection (CID) dataset. is the second stage of work with this dataset, emphasizing incorporation anomaly detection in modeling prediction cyber-attacks. The SVMmethod for classification used as benchmark method (from previous study [1]), approaches compare so-called "one class" SVMs thresholded Mahalanobis distance define support regions. Results performance methods, investigate joint detection. dataset DARPA/KDD-99 publicly available features from network packets classified into non-attack four attack categories.

参考文章(10)
D. Dubois, M. Gokhale, GIGABIT RATE NETWORK INTRUSION DETECTION TECHNOLOGY Conference title not supplied, Conference location not supplied, Conference dates not supplied. ,(2001)
James Franklin, The elements of statistical learning : data mining, inference,and prediction The Mathematical Intelligencer. ,vol. 27, pp. 83- 85 ,(2005) , 10.1007/BF02985802
Thorsten Joachims, Making large scale SVM learning practical Technical reports. ,(1999) , 10.17877/DE290R-14262
BSCH OLKOPF, C Burges, A Smola, Advances in kernel methods: support vector learning international conference on neural information processing. ,(1999) , 10.5555/299094
R.P. Lippmann, D.J. Fried, I. Graf, J.W. Haines, K.R. Kendall, D. McClung, D. Weber, S.E. Webster, D. Wyschogrod, R.K. Cunningham, M.A. Zissman, Evaluating intrusion detection systems: the 1998 DARPA off-line intrusion detection evaluation darpa information survivability conference and exposition. ,vol. 2, pp. 12- 26 ,(2000) , 10.1109/DISCEX.2000.821506
Bernhard Schölkopf, John C. Platt, John Shawe-Taylor, Alex J. Smola, Robert C. Williamson, Estimating the Support of a High-Dimensional Distribution Neural Computation. ,vol. 13, pp. 1443- 1471 ,(2001) , 10.1162/089976601750264965
Ronald Christensen, Plane answers to complex questions: the theory of linear models Journal of the American Statistical Association. ,vol. 84, pp. 1100- ,(1987) , 10.1007/978-3-030-32097-3
Chih-Chung Chang, Chih-Jen Lin, LIBSVM ACM Transactions on Intelligent Systems and Technology. ,vol. 2, pp. 1- 27 ,(2011) , 10.1145/1961189.1961199
Ronald Christensen, Martin W. Bauer, Advanced linear modeling ,(2001)
Ronald Christensen, Plane Answers to Complex Questions Springer Texts in Statistics. ,(1996) , 10.1007/978-1-4757-2477-6