We introduce an algorithm called LERAD that learns rules for finding rare events in nominal time-series data with long range dependencies. We use LERAD to find anomalies in network packets and TCP sessions to detect novel intrusions. We evaluated LERAD on the 1999 DARPA/Lincoln Laboratory intrusion detection evaluation data set and on traffic collected in a university departmental server environment.
No takes yet. Share an insight, caveat, or question.
Mahoney et al. (2003) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: