An enhanced CUSUM algorithm for anomaly detection

0Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Anomaly detection has been extensively studied in the last two decades. Features are usually selected or created at first for characterizing behaviours of networks, users or systems, and then anomaly detection algorithms are developed and applied. However, such traditional network anomaly detection systems detect a limited number of attack types and report a huge number of false alarms due to lack of proper features and inherent weakness of anomaly detection algorithms. In order to minimize the number of false alerts and maximize the detection accuracy, we propose in this chapter an enhanced CUSUM algorithm for network anomaly detection, modelling various features from different sources and reporting alerts according to some decision strategies. The experimental evaluation with the 1999 DARPA intrusion detection evaluation dataset shows an empirical study of applying the proposed enhanced CUSUM algorithm for detecting successfully some network attacks.

Cite

CITATION STYLE

APA

Lu, W., & Xue, L. (2017). An enhanced CUSUM algorithm for anomaly detection. In Information Security Practices: Emerging Threats and Perspectives (pp. 83–96). Springer International Publishing. https://doi.org/10.1007/978-3-319-48947-6_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free