Automatic feature selection for anomaly detection

Research output: Contributions to collected editions/worksArticle in conference proceedingsResearchpeer-review

Authors

  • Marius Kloft
  • Ulf Brefeld
  • Patrick Düssel
  • Christian Gehl
  • Pavel Laskov

A frequent problem in anomaly detection is to decide among different feature sets to be used. For example, various features are known in network intrusion detection based on packet headers, content byte streams or application level protocol parsing. A method for automatic feature selection in anomaly detection is proposed which determines optimal mixture coeffcients for various sets of features. The method generalizes the support vector data description (SVDD) and can be expressed as a semi-innite linear program that can be solved with standard techniques. The case of a single feature set can be handled as a particular case of the proposed method. The experimental evaluation of the new method on unsanitized HTTP data demonstrates that detectors using automatically selected features attain competitive performance, while sparing practitioners from a priori decisions on feature sets to be used.

Original languageEnglish
Title of host publicationProceedings of the 1st ACM workshop on Workshop on AISec
EditorsDirk Balfanz, Jessica Staddon
Number of pages6
Place of PublicationNew York
PublisherAssociation for Computing Machinery, Inc
Publication date27.10.2008
Pages71-76
ISBN (print)978-1-60558-291-7
DOIs
Publication statusPublished - 27.10.2008
Externally publishedYes
EventAISec '08 - Alexandria, United States
Duration: 27.10.200831.10.2008
Conference number: 1

    Research areas

  • Informatics - Anomaly detection, Feature selection, Intrusion detection, Machine learning, Multiple kernel learning, Network security, Support vector data description
  • Business informatics

DOI

Recently viewed

Publications

  1. The Forgotten Function of Forgetting
  2. Kit based motion generator for a soft walking robot
  3. Structural Synthesis of Parallel Robots with Unguided Linear Actuators
  4. Parameterized Synthetic Image Data Set for Fisheye Lens
  5. Document assignment in multi-site search engines
  6. Detection time analysis of propulsion system fault effects in a hexacopter
  7. On the utility of indirect methods for detecting faking
  8. On the origin of passive rotation in rotational joints, and how to calculate it
  9. Homogenization methods for multi-phase elastic composites with non-elliptical reinforcements
  10. Mining Implications From Data
  11. Early Detection of Faillure in Conveyor Chain Systems by Wireless Sensor Node
  12. Trait-based approaches to analyze links between the drivers of change and ecosystem services
  13. Design, Modeling and Control of an Over-actuated Hexacopter Tilt-Rotor
  14. Robust Control of Excavation Mobile Robot with Dynamic Triangulation Vision
  15. Optimal dynamic scale and structure of a multi-pollution economy
  16. An error management perspective on audit quality
  17. A high-resolution approach for the spatiotemporal analysis of forest canopy space using terrestrial laser scanning data
  18. Obstacle Coordinates Transformation from TVS Body-Frame to AGV Navigation-Frame
  19. Impulsive Feedback Linearization for Decoupling of a Constant Disturbance with Low Relative Degree to Control Maglev Systems
  20. A Sliding Mode Control with a Bang-Bang Observer for Detection of Particle Pollution
  21. Global Finite-Time Stabilization of Planar Linear Systems With Actuator Saturation
  22. A Lyapunov based PI controller with an anti-windup scheme for a purification process of potable water
  23. The Impact of AGVs and Priority Rules in a Real Production Setup – A Simulation Study
  24. Performance of process-based models for simulation of grain N in crop rotations across Europe
  25. A Control of an Electromagnetic Actuator Using Model Predictive Control
  26. Passive Rotation Compensation in Parallel Kinematics Using Quaternions
  27. Educational reconstruction as model for the theory-based design of student-centered learning environments in electrical engineering courses
  28. An isomorphism between polynomial eigenfunctions of the transfer operator and the Eichler cohomology for modular groups
  29. A geometric approach for the design and control of an electromagnetic actuator to optimize its dynamic performance
  30. Machine vision system errors for unmanned aerial vehicle navigation
  31. Modernizing persistence–bioaccumulation–toxicity (PBT) assessment with high throughput animal-free methods
  32. Factor structure and measurement invariance of the Students’ Self-report Checklist of Social and Learning Behaviour (SSL)
  33. A Structure and Content Prompt-based Method for Knowledge Graph Question Answering over Scholarly Data
  34. Simple relay non-linear PD control for faster and high-precision motion systems with friction
  35. Controlling a Bank Model Economy by Using an Adaptive Model Predictive Control with Help of an Extended Kalman Filter
  36. Reading Comprehension as Embodied Action: Exploratory Findings on Nonlinear Eye Movement Dynamics and Comprehension of Scientific Texts
  37. WHICH ESTIMATION SITUATIONS ARE RELEVANT FOR A VALID ASSESSMENT OF MEASUREMENT ESTIMATION SKILLS
  38. Individual Scans Fusion in Virtual Knowledge Base for Navigation of Mobile Robotic Group with 3D TVS
  39. DISKNET – A Platform for the Systematic Accumulation of Knowledge in IS Research
  40. Image compression based on periodic principal components
  41. On the computation of the warping function and the torsional properties of thin-walled crosssections of prismatic beams
  42. Within-individual leaf trait variation increases with phenotypic integration in a subtropical tree diversity experiment
  43. Proxy Indicators for the Quality of Open-domain Dialogues
  44. A Comparative Study for Fisheye Image Classification
  45. Functional Richness and Relative Resilience of Bird Communities in Regions with Different Land Use Intensities
  46. Pressure fault recognition and compensation with an adaptive feedforward regulator in a controlled hybrid actuator within engine applications
  47. Masked Autoencoder Pretraining for Event Classification in Elite Soccer
  48. A longitudinal multilevel CFA-MTMM model for interchangeable and structurally different methods