Intrusion detection using noisy training data

2Citations
Citations of this article
1Readers
Mendeley users who have this article in their library.
Get full text

Abstract

One of the greatest difficulties in anomaly detection is to obtain training data having no intrusions. In anomaly detection, training data should be obtained from the target system. If there exists an intrusion in this data, the trained intrusion detection system will assume that it is normal and will not detect subsequent occurrences. In this paper, we present a system call based anomaly detection method that can detect intrusions effectively even though the training set contains intrusions. This scheme exploits the property that if there is an intrusion hidden in the training data, it is likely to consist of a sequence of elements having low frequencies of occurrence. Compared with the previous schemes, simulation results show that with the training data containing intrusions the proposed method has lower false positive rates and higher detection rates. Moreover, for clean training data our method and the previous schemes shows similar performance. The proposed method can be viewed as an approach to increase practicality of anomaly detection and to enhance reliability of security policy. © Springer-Verlag 2004.

Cite

CITATION STYLE

APA

Park, Y., Lee, J., & Cho, Y. (2004). Intrusion detection using noisy training data. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 3043, 547–556. https://doi.org/10.1007/978-3-540-24707-4_66

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free