PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 1, 201224 citations

Anomaly intrusion detection based upon data mining techniques and fuzzy logic

View Full Paper
YYYingbing YuHWHan Wu

Key Points

Key points are not available for this paper at this time.

Abstract

Intrusion detection systems (IDSs) attempt to identify attacks by comparing new data to predefined signatures known to be malicious (misuse IDSs) or to a model of normal behavior (anomaly-based IDSs). Anomaly intrusion detection approaches have the advantage of detecting previously unknown or new attacks, but suffer from the possible high false alarms due to the problem of behavior drifting and the difficulty of building an adaptive model. In this paper, we propose a model based on the data mining technique - naïve Bayes classification to classify an input event (system call sequences generated from privileged processes) as “normal” or “anomalous” to detect system anomalous behavior. The independent frequency of each system call from a process collected under the normal conditions is the basis for the classifier. The ratio of the probability of a sequence from a process and the probability NOT from the process serves as the input of a fuzzy system for the classification. Experimental results in a data set consisting of both normal and intrusion traces show that the model can successfully detect most of intrusion traces with a very low false alarm rate.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Yu et al. (2012) studied this question.

synapsesocial.com/papers/6a12fcd117455f99e89e6e86https://doi.org/10.1109/icsmc.2012.6377776
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Anomaly Detection over Noisy Data Using Learned Probability Distributions2000 · 489 citations
  2. 2Computer security threat monitoring and surveillance1980 · 1,355 citations
  3. 3A sense of self for Unix processes2002 · 865 citations
  4. 4Computer immunology1997 · 854 citations
  5. 5Machine learning techniques for the computer security domain of anomaly detection2000 · 115 citations