A novel anomaly detection using small training sets

0Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Anomaly detection is an essential component of the protection mechanism against novel attacks. Traditional methods need very large volume of purely training dataset, which is expensive to classify it manually. A new method for anomaly intrusion detection is proposed based on supervised clustering and Markov chain model, which is designed to train from a small set of normal data. After short system call sequences are clustered, Markov chain is used to learn the relationship among these clusters and classify the normal or abnormal. The observed behavior of the system is analyzed to infer the probability that the Markov chain of the norm profile supports the observed behavior. Markov information source entropy and condition entropy are used to select parameters. The experiments have showed that the method is effective to detect anomalistic behaviors, and enjoys better generalization ability when a small number of training dataset is used only. © Springer-Verlag Berlin Heidelberg 2005.

Cite

CITATION STYLE

APA

Yin, Q., Shen, L., Zhang, R., & Li, X. (2005). A novel anomaly detection using small training sets. In Lecture Notes in Computer Science (Vol. 3578, pp. 258–263). Springer Verlag. https://doi.org/10.1007/11508069_34

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free