Active learning for network intrusion detection

Publikation: Beiträge in SammelwerkenAufsätze in KonferenzbändenForschungbegutachtet

Authors

Anomaly detection for network intrusion detection is usually considered an unsupervised task. Prominent techniques, such as one-class support vector machines, learn a hypersphere enclosing network data, mapped to a vector space, such that points outside of the ball are considered anomalous. However, this setup ignores relevant information such as expert and background knowledge. In this paper, we rephrase anomaly detection as an active learning task. We propose an effective active learning strategy to query low-confidence observations and to expand the data basis with minimal labeling effort. Our empirical evaluation on network intrusion detection shows that our approach consistently outperforms existing methods in relevant scenarios.
OriginalspracheEnglisch
TitelAISec '09 : Proceedings of the ACM Conference on Computer and Communications Security
HerausgeberDirk Balfanz, Jessica Staddon
Anzahl der Seiten8
ErscheinungsortNew York
VerlagAssociation for Computing Machinery, Inc
Erscheinungsdatum09.11.2009
Seiten47-54
ISBN (Print)978-1-60558-781-3
DOIs
PublikationsstatusErschienen - 09.11.2009
Extern publiziertJa
Veranstaltung2nd ACM Workshop on Security and Artificial Intelligence, AISec '09, Co-located with the 16th ACM Computer and Communications Security Conference - Chicago, USA / Vereinigte Staaten
Dauer: 09.11.200913.11.2009
Konferenznummer: 2

DOI

Zuletzt angesehen

Publikationen

  1. Introduction
  2. Natural enemy diversity reduces temporal variability in wasp but not bee parasitism
  3. WHICH ESTIMATION SITUATIONS ARE RELEVANT FOR A VALID ASSESSMENT OF MEASUREMENT ESTIMATION SKILLS
  4. Personalization strategies in digital mental health interventions: a systematic review and conceptual framework for depressive symptoms
  5. An isomorphism between polynomial eigenfunctions of the transfer operator and the Eichler cohomology for modular groups
  6. Continental mapping of forest ecosystem functions reveals a high but unrealised potential for forest multifunctionality.
  7. Rethinking the Spatiality of Spatial Planning
  8. Building trust
  9. How many organic compounds are graph-theoretically nonplanar?
  10. Continued logarithm representation of real numbers
  11. Dynamic Semantic Web Content for Museum Guides
  12. Intelligence assessment with computer simulations
  13. Development and application of a simplified sampling method for volatile polyfluorinated alkyl substances in indoor and environmental air
  14. Identification of Parameters and States in PMSMs
  15. Enacting migration through data practices
  16. A Note on Pensions and Firm Performance
  17. Managing Multiple Logics: The Role of Performance Measurement Systems in Social Enterprises
  18. Short run comovement, persistent shocks and the business cycle
  19. Effect of erbium modification on the microstructure, mechanical and corrosion characteristics of binary Mg-Al alloys
  20. How do students and teachers deal with mathematical modelling problems?
  21. Theoretical Practices
  22. PID Controller Application in a Gimbal Construction for Camera Stabilization and Tracking
  23. Extending talk on a prescribed discussion topic in a learner-native speaker eTandem learning task
  24. Experimental investigation of the fluid-structure interaction during deep drawing of fiber metal laminates in the in-situ hybridization process
  25. Knowledge Decolonization à la Grounded Theory