期刊文献+

An entropy-based unsupervised anomaly detection pattern learning algorithm

An entropy-based unsupervised anomaly detection pattern learning algorithm
下载PDF
导出
摘要 Currently, most anomaly detection pattern learning algorithms require a set of purely normal data from which they train their model. If the data contain some intrusions buried within the training data, the algorithm may not detect these attacks because it will assume that they are normal. In reality, it is very hard to guarantee that there are no attack items in the collected training data. Focusing on this problem, in this paper, firstly a new anomaly detection measurement is proposed according to the probability characteristics of intrusion instances and normal instances. Secondly, on the basis of anomaly detection measure, we present a clustering-based unsupervised anomaly detection patterns learning algorithm, which can overcome the shortage above. Finally, some experiments are conducted to verify the proposed algorithm is valid. Currently, most anomaly detection pattern learning algorithms require a set of purely normal data from which they train their model. If the data contain some intrusions buried within the training data, the algorithm may not detect these attacks because it will assume that they are normal. In reality, it is very hard to guarantee that there are no attack items in the collected training data. Focusing on this problem, in this paper, firstly a new anomaly detection measurement is proposed according to the probability characteristics of intrusion instances and normal instances. Secondly, on the basis of anomaly detection measure, we present a clustering-based unsupervised anomaly detection patterns learning algorithm, which can overcome the shortage above. Finally, some experiments are conducted to verify the proposed algorithm is valid.
出处 《Journal of Harbin Institute of Technology(New Series)》 EI CAS 2005年第1期81-85,共5页 哈尔滨工业大学学报(英文版)
关键词 计算机技术 信息安全 探测模式 入侵探测技术 网络技术 anomaly detection intrusion detection computer security pattern learning
  • 相关文献

参考文献10

  • 1HANJW,KAMBERM.DataMining:ConceptsandTechniques[]..2001
  • 2PROVOSTF,FAWCETTT,KOHAVIR.Thecasea gainstaccuracyestimationforcomparinginductionalgo rithms[].ProceedingsofthethInternationalConfer enceonMachineLearning.1998
  • 3LEESC,HEINBUCHDV.Traininganeural networkbasedintrusiondetectortorecognizenovelattacks[].IEEETransactionsonSystemsMan andCybernetics—PartA:SystemsandHumans.2001
  • 4FAYYADUM,SHAPIROGP,SMUTHP, etal.Ad vancesinKnowledgeDiscoveryandDataMining[]..1996
  • 5BLAHUTR.PrinciplesandPracticeofInformationTheo ry[]..1987
  • 6VENTURAD.OnDiscretizationasaPreprocessingStepforSupervisedLearningModels[]..1995
  • 7Denning D E,An intrusion-detection model. IEEE Transactions on Software Engineering . 1987
  • 8Lee W.A Data Mining Framework for Constructing Features and Models for Intrusion Detection Systems[]..1999
  • 9BARBARA D,COUTO J,JAJODIA S,et al.ADAM:detecting intrusions by data mining[].Proceedings of the IEEE Workshop on Information Assurance and Security.2001
  • 10WARRENDER C,FORREST S,PEARLMUTTER B.Detecting intrusions using system calls: Alternative data models[].IEEE Symposium on Security and Privacy.1999

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部