Active learning for network intrusion detection

Research output: Contributions to collected editions/worksArticle in conference proceedingsResearchpeer-review

Authors

Anomaly detection for network intrusion detection is usually considered an unsupervised task. Prominent techniques, such as one-class support vector machines, learn a hypersphere enclosing network data, mapped to a vector space, such that points outside of the ball are considered anomalous. However, this setup ignores relevant information such as expert and background knowledge. In this paper, we rephrase anomaly detection as an active learning task. We propose an effective active learning strategy to query low-confidence observations and to expand the data basis with minimal labeling effort. Our empirical evaluation on network intrusion detection shows that our approach consistently outperforms existing methods in relevant scenarios.

Original languageEnglish
Title of host publicationAISec '09 : Proceedings of the ACM Conference on Computer and Communications Security
EditorsDirk Balfanz, Jessica Staddon
Number of pages8
Place of PublicationNew York
PublisherAssociation for Computing Machinery, Inc
Publication date09.11.2009
Pages47-54
ISBN (print)978-1-60558-781-3
DOIs
Publication statusPublished - 09.11.2009
Externally publishedYes
Event2nd ACM Workshop on Security and Artificial Intelligence, AISec '09, Co-located with the 16th ACM Computer and Communications Security Conference - Chicago, United States
Duration: 09.11.200913.11.2009
Conference number: 2

    Research areas

  • Informatics - Active learning, Anomaly detection, Intrusion detection, Machine learning, Network security, Support vector data description
  • Business informatics

DOI

Recently viewed

Publications

  1. Complexity of traffic scenes and EEG-measures of processing workload in car driving
  2. Constraints are the solution, not the problem
  3. Effect of gap distortion on the field splitting of collective modes in superfluid He3-B
  4. Jackson networks in nonautonomous random environments
  5. The generative drawing principle in multimedia learning
  6. Aspect-oriented software development
  7. Using corpus-linguistic methods to track longitudinal development
  8. The buffering effect of selection, optimization, and compensation strategy use on the relationship between problem solving demands and occupational well-being
  9. Performance of process-based models for simulation of grain N in crop rotations across Europe
  10. Self-tuning of a kalman filter applied in a DC drive and in a kalman-based sensor
  11. Effectiveness of a Web-Based Cognitive Behavioural Intervention for Subthreshold Depression
  12. Overcoming Multi-legacy Application Challenges through Building Dynamic Capabilities for Low-Code Adoption
  13. Constraint breeds creativity
  14. Gaining deep leverage? Reflecting and shaping real-world lab impacts through leverage points
  15. Action rate models for predicting actions in soccer
  16. Correlation of Microstructure and Local Mechanical Properties Along Build Direction for Multi-layer Friction Surfacing of Aluminum Alloys
  17. Learning from Erroneous Examples: When and How do Students Benefit from them?
  18. Perception and Inference
  19. Action Errors, Error Management, and Learning in Organizations
  20. From Knowledge to Application
  21. Development and application of a laboratory flux measurement system (LFMS) for the investigation of the kinetics of mercury emissions from soils
  22. How, when and why do negotiators use reference points?
  23. Repeat Receipts: A device for generating visible data in market research focus groups
  24. Image compression based on periodic principal components
  25. On the computation of the warping function and the torsional properties of thin-walled crosssections of prismatic beams
  26. Different facets of tree sapling diversity influence browsing intensity by deer dependent on spatial scale
  27. Playing in the Spaces: Anarchism in the Classroom
  28. Reality-Based Tasks with Complex-Situations
  29. Organizing Events for Configuring and Maintaining Creative Fields
  30. Pressure fault recognition and compensation with an adaptive feedforward regulator in a controlled hybrid actuator within engine applications
  31. Using Language Learning Resources on YouTube
  32. Efficacy of an internet and app-based gratitude intervention in reducing repetitive negative thinking and mechanisms of change in the intervention's effect on anxiety and depression