The use of anomaly-based classification of intrusions has increased significantly for Intrusion Detection Systems. Large number of training data samples and a good 'feature set' are two primary requirements to build effective classification models with machine learning algorithms. Since the amount of data available for malicious traffic will often be small compared to the available traces of benign traffic, extraction of 'good' features which enable detection of malicious traffic is a challenging area of work.
No takes yet. Share an insight, caveat, or question.
Narang et al. (2013) studied this question.
Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context: