A real-time intrusion-detection expert system (IDES) is described that observed user behavior on a monitored computer system and adaptively learns what is normal for individual users, groups, remote hosts, and the overall system behavior. Observed behavior is flagged as a potential intrusion if it deviates significantly from the expected behavior or if it triggers a rule in the expert-system rule base. It is shown that because IDES combines a statistical user profile approach with a rule-based expert system that characterizes intrusions, it has the potential to become a strong intrusion-detection system. The IDES prototype is capable of detecting anomalous behavior, as evidenced by preliminary experiments, in real time.< <ETX xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">></ETX>
No takes yet. Share an insight, caveat, or question.
Teresa F. Lunt (2003) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: