Intrusion detection in unlabeled data with quarter-sphere support vector machines
Abstract
Practical application of data mining and machine learning techniques to intrusion detection is often hindered by the difficulty to produce clean data for the training. To address this problem a geometric framework for unsupervised anomaly detection has been recently proposed. In this framework, the data is mapped into a feature space, and anomalies are detected as the entries in sparsely populated regions. In this contribution we propose a novel formulation of a one-class Support Vector Machine (SVM) specially designed for typical IDS data features. The key idea of our "quarter-sphere" algorithm is to encompass the data with a hypersphere anchored at the center of mass of the data in feature space. The proposed method and its behavior on varying percentages of attacks in the data is evaluated on the KDDCup 1999 dataset.
- Citation
- BibTeX
Laskov, P., Christin, S. & Kotenko, I.,
(2004).
Intrusion detection in unlabeled data with quarter-sphere support vector machines.
In:
Flegel, U. & Meier, M.
(Hrsg.),
Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004.
Bonn:
Gesellschaft für Informatik e.V..
(S. 71-82).
@inproceedings{mci/Laskov2004,
author = {Laskov, Pavel AND Christin, Schäfer AND Kotenko, Igor},
title = {Intrusion detection in unlabeled data with quarter-sphere support vector machines},
booktitle = {Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004},
year = {2004},
editor = {Flegel, Ulrich AND Meier, Michael} ,
pages = { 71-82 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Laskov, Pavel AND Christin, Schäfer AND Kotenko, Igor},
title = {Intrusion detection in unlabeled data with quarter-sphere support vector machines},
booktitle = {Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004},
year = {2004},
editor = {Flegel, Ulrich AND Meier, Michael} ,
pages = { 71-82 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Dateien | Groesse | Format | Anzeige | |
---|---|---|---|---|
GI.Proceedings.46-5.pdf | 237.0Kb | View/ |
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Send Feedback
More Info
ISBN: 3-88579-375-X
ISSN: 1617-5468
xmlui.MetaDataDisplay.field.date: 2004
Language:
(en)

Content Type: Text/Conference Paper