Publication | Closed Access
A Machine Learning Approach to Anomaly Detection
81
Citations
19
References
2003
Year
Unknown Venue
Anomaly DetectionMachine LearningData ScienceData MiningPattern RecognitionInformation SecurityMachine Learning ApproachOutlier DetectionKnowledge DiscoveryIntrusion DetectionThreat DetectionInformation ForensicsIntrusion Detection SystemNovelty DetectionAnomaly Detection ModelsComputer ScienceSignature DetectionEngineering
Much of the intrusion detection research focuses on signature (misuse) detection, where models are built to recognize known attacks. However, signature detection, by its nature, cannot detect novel attacks. Anomaly detection focuses on modeling the normal behavior and identifying significant deviations, which could be novel attacks. In this paper we explore two machine learning methods that can construct anomaly detection models from past behavior. The first method is a rule learning algorithm that characterizes normal behavior in the absence of labeled attack data. The second method uses a clustering algorithm to identify outliers.
| Year | Citations | |
|---|---|---|
Page 1
Page 1