Active learning for network intrusion detection

Research output: Contributions to collected editions/worksArticle in conference proceedingsResearchpeer-review

Authors

Anomaly detection for network intrusion detection is usually considered an unsupervised task. Prominent techniques, such as one-class support vector machines, learn a hypersphere enclosing network data, mapped to a vector space, such that points outside of the ball are considered anomalous. However, this setup ignores relevant information such as expert and background knowledge. In this paper, we rephrase anomaly detection as an active learning task. We propose an effective active learning strategy to query low-confidence observations and to expand the data basis with minimal labeling effort. Our empirical evaluation on network intrusion detection shows that our approach consistently outperforms existing methods in relevant scenarios.

Original languageEnglish
Title of host publicationAISec '09 : Proceedings of the ACM Conference on Computer and Communications Security
EditorsDirk Balfanz, Jessica Staddon
Number of pages8
Place of PublicationNew York
PublisherAssociation for Computing Machinery, Inc
Publication date09.11.2009
Pages47-54
ISBN (print)978-1-60558-781-3
DOIs
Publication statusPublished - 09.11.2009
Externally publishedYes
Event2nd ACM Workshop on Security and Artificial Intelligence, AISec '09, Co-located with the 16th ACM Computer and Communications Security Conference - Chicago, United States
Duration: 09.11.200913.11.2009
Conference number: 2

    Research areas

  • Informatics - Active learning, Anomaly detection, Intrusion detection, Machine learning, Network security, Support vector data description
  • Business informatics

DOI

Recently viewed

Publications

  1. Global Finite-Time Stabilization of Planar Linear Systems With Actuator Saturation
  2. A Lyapunov based PI controller with an anti-windup scheme for a purification process of potable water
  3. Embarrassment as a public vs. private emotion and symbolic coping behaviour
  4. The Creation of the Concept through the Interaction of Philosophy with Science and Art
  5. Strategies of postural control in static and in dynamic testing situations
  6. Design of an Information-Based Distributed Production Planning System
  7. Understanding and Supporting Management Decision-Making
  8. Topic selection and development in learner-native speaker voice-based telecollaborative discourse
  9. Adaptive control of the nonlinear dynamic behavior of the cantilever-sample system of an atomic force microscope
  10. Transductive support vector machines for structured variables
  11. Exploring transition research as transformative science
  12. »HOW TO MAKE YOUR OWN SAMPLES«
  13. Performance of process-based models for simulation of grain N in crop rotations across Europe
  14. Aspect-oriented software development
  15. Learning shortest paths in word graphs
  16. Distributable Modular Software Framework for Manufacturing Systems
  17. Measuring Learning Styles with Questionnaires Versus Direct Observation of Preferential Choice Behavior in Authentic Learning Situations
  18. Oddih
  19. “Ideation is Fine, but Execution is Key”
  20. Towards a spatial understanding of identity play
  21. Resolving the Complexity-Flexibility Dilemma in Multi-Issue Negotiations: Nested Bracketing as a Strategy to Enhance Negotiation Outcomes
  22. Developing a sustainable platform for entity annotation benchmarks
  23. Machine Learning For Determining Planned Order Lead Times In Job Shop Production: A Systematic Review Of Input Factors And Applied Methods
  24. Foreign bias in institutional portfolio allocation
  25. Gaining deep leverage? Reflecting and shaping real-world lab impacts through leverage points
  26. Preventive Diagnostics for cardiovascular diseases based on probabilistic methods and description logic
  27. Action rate models for predicting actions in soccer
  28. Rethink Textile Production - Developing sustainable concepts for textile industry using production simulation
  29. Pluralism and diversity: Trends in the use and application of ordination methods 1990-2007
  30. Failing and the perception of failure in student-driven transdisciplinary projects