Automatic feature selection for anomaly detection

Research output: Contributions to collected editions/worksArticle in conference proceedingsResearchpeer-review

Authors

  • Marius Kloft
  • Ulf Brefeld
  • Patrick Düssel
  • Christian Gehl
  • Pavel Laskov

A frequent problem in anomaly detection is to decide among different feature sets to be used. For example, various features are known in network intrusion detection based on packet headers, content byte streams or application level protocol parsing. A method for automatic feature selection in anomaly detection is proposed which determines optimal mixture coeffcients for various sets of features. The method generalizes the support vector data description (SVDD) and can be expressed as a semi-innite linear program that can be solved with standard techniques. The case of a single feature set can be handled as a particular case of the proposed method. The experimental evaluation of the new method on unsanitized HTTP data demonstrates that detectors using automatically selected features attain competitive performance, while sparing practitioners from a priori decisions on feature sets to be used.

Original languageEnglish
Title of host publicationProceedings of the 1st ACM workshop on Workshop on AISec
EditorsDirk Balfanz, Jessica Staddon
Number of pages6
Place of PublicationNew York
PublisherAssociation for Computing Machinery, Inc
Publication date27.10.2008
Pages71-76
ISBN (print)978-1-60558-291-7
DOIs
Publication statusPublished - 27.10.2008
Externally publishedYes
EventAISec '08 - Alexandria, United States
Duration: 27.10.200831.10.2008
Conference number: 1

    Research areas

  • Informatics - Anomaly detection, Feature selection, Intrusion detection, Machine learning, Multiple kernel learning, Network security, Support vector data description
  • Business informatics

DOI

Recently viewed

Publications

  1. Challenges and boundaries in implementing social return on investment
  2. Discriminative clustering for market segmentation
  3. Turning Good Intentions Into Actions by Using the Health Action Process Approach to Predict Adherence to Internet-Based Depression Prevention
  4. A common European asylum system? How variation in Member States’ administrative capacity undermines EU asylum harmonisation
  5. Optimal control strategies for PMSM with a decoupling super twisting SMC and inductance estimation in the presence of saturation
  6. Timing matters: Distinct effects of nitrogen and phosphorus fertilizer application timing on root system architecture responses
  7. Promoting physical activity in worksite settings
  8. Intelligent software system for replacing a force sensor in the case of clearance measurement
  9. Effectiveness of Web- and Mobile-Based Treatment of Subthreshold Depression With Adherence-Focused Guidance
  10. Vocational identity as a mediator of the relationship between core self-evaluations and life and job satisfaction
  11. The explanatory power of Carnegie Classification in predicting engagement indicators
  12. Support from the Internet for Individuals with Mental Disorders
  13. Vibration analysis based on the spectrum kurtosis for adjustment and monitoring of ball bearing radial clearance
  14. Mechanisms of teleological change
  15. Energy-aware system design for autonomous wireless sensor nodes
  16. Ein echter Gedanke reicht weit
  17. Give and take frames in shared-resource negotiations
  18. Dimension theoretical properties of generalized Baker's transformations
  19. EU decision-making in asylum policy
  20. At what price? IP-related thoughts on new business models for space information
  21. Assessing the costs and cost-effectiveness of ICare internet-based interventions (protocol)
  22. Facing the heat
  23. Crowdsourcing Hypothesis Tests
  24. Salivary cues
  25. Control of Permanent Magnet Synchronous Motors for Track Applications
  26. Interactivity, Interpassivity and Possibilities Beyond Dichotomy
  27. CoLab
  28. Dynamische Bestandsdimensionierung
  29. Leverage points for sustainability transformation
  30. Antidepressants
  31. A klímavédelem alapvető feladatai
  32. Editorial
  33. Rechtschreiben unterrichten
  34. So macht man Karriere
  35. Integrating highly diverse invertebrates into broad-scale analyses of cross-taxon congruence across the Palaearctic
  36. The depositional environments of Schöningen 13 II-4 and their archaeological implications
  37. Kooperation mit Migranteneltern
  38. I will probably fail