Anomaly Detection Enhanced Classification in Computer Intrusion Detection

  • Authors:
  • Mike Fugate;James R. Gattiker

  • Affiliations:
  • -;-

  • Venue:
  • SVM '02 Proceedings of the First International Workshop on Pattern Recognition with Support Vector Machines
  • Year:
  • 2002

Quantified Score

Hi-index 0.01

Visualization

Abstract

This paper describes experiences and results applying Support Vector Machine (SVM) to a Computer Intrusion Detection (CID) dataset. This is the second stage of work with this dataset, emphasizing incorporation of anomaly detection in the modeling and prediction of cyber-attacks. The SVMmethod for classification is used as a benchmark method (from previous study [1]), and the anomaly detection approaches compare so-called "one class" SVMs with a thresholded Mahalanobis distance to define support regions. Results compare the performance of the methods, and investigate joint performance of classification and anomaly detection. The dataset used is the DARPA/KDD-99 publicly available dataset of features from network packets classified into non-attack and four attack categories.