Anomaly Detection Using Time Index Differences of Identical Symbols with and without Training Data

  • Authors:
  • Stefan Jan Skudlarek;Hirosuke Yamamoto

  • Affiliations:
  • Graduate School Of Frontier Sciences, University of Tokyo, Chiba, Japan 277-8561;Graduate School Of Frontier Sciences, University of Tokyo, Chiba, Japan 277-8561

  • Venue:
  • ADMA '09 Proceedings of the 5th International Conference on Advanced Data Mining and Applications
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Anomaly detection or novelty detection has emerged as a powerful tool for masquerade detection during the past decade. However, the strong dependence of previous methods on uncontaminated training data is a matter of concern. We introduce a novel masquerade detection algorithm based on a statistical test for system parameter drift of time series data. The approach presented may exploit attack-free training data if provided, but is not dependent on it. It transforms the string of commands into a symbol sequence, respectively using the average time index difference of symbols identical to the symbol found at a particular index for anomaly detection. We evaluated the method using the standard data set provided by Schonlau et al., both including and excluding the use of training data. We report the results achieved with and without training data, and compare them to the results attained by several conventional methods using training data.