DocumentCode :
1935919
Title :
CH-SVM Based Network Anomaly Detection
Author :
Zhang, Xue-Qin ; Gu, Chun-Hua
Author_Institution :
East China Univ. of Sci. & Technol., Shanghai
Volume :
6
fYear :
2007
fDate :
19-22 Aug. 2007
Firstpage :
3261
Lastpage :
3266
Abstract :
Network anomaly detection is a critical task to ensure network security. With increasing network traffic, detecting network anomaly would require solving a large-scale pattern classification problem that often contains millions of training vectors. Each training vector may represent a particular signature of network traffic pattern and some of them may be linked to security breaching activities that need to be detected and eradicated. In this paper, a popular statistical learning algorithm known as the support vector machine (SVM) was consider to solve the network anomaly detection problem. However, it is well known that SVM would require excessively long computing time and exceedingly large amount of memory when number of training vectors becomes huge. Hence, direct application of the standard SVM algorithm to solve large-scale network anomaly detection problems is impractical. In this paper, based on computational geometry theory, a new algorithm called convex-hull SVM (CH-SVM) was proposed, which can yield the same solution as original SVM while using significantly less training data, and hence less computing time. Then experiments were done on KDD´99 intrusion detection dataset to compare the performance of the proposed algorithm to a standard SVM and observed reduced training time and improved classification accuracy.
Keywords :
authorisation; computational geometry; statistical analysis; support vector machines; telecommunication security; computational geometry theory; convex-hull SVM; network anomaly detection; network security; statistical learning algorithm; support vector machine; Computer networks; Cybernetics; Intrusion detection; Large-scale systems; Machine learning; Quadratic programming; Statistical learning; Support vector machine classification; Support vector machines; Telecommunication traffic; Anomaly detection; Convex hull; Support vector machine;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Machine Learning and Cybernetics, 2007 International Conference on
Conference_Location :
Hong Kong
Print_ISBN :
978-1-4244-0973-0
Electronic_ISBN :
978-1-4244-0973-0
Type :
conf
DOI :
10.1109/ICMLC.2007.4370710
Filename :
4370710
Link To Document :
بازگشت