Title :
A Higher Order Collective Classifier for detecting and classifying network events
Author :
Menon, Vikas ; Pottenger, William M.
Author_Institution :
Dept. of Comput. Sci., Rutgers Univ., New Brunswick, NJ, USA
Abstract :
Labeled data is scarce. Most statistical machine learning techniques rely on the availability of a large labeled corpus for building robust models for prediction and classification. In this paper we present a Higher Order Collective Classifier (HOCC) based on higher order learning, a statistical machine learning technique that leverages latent information present in co-occurrences of items across records. These techniques violate the IID assumption that underlies most statistical machine learning techniques and have in prior work outperformed first order techniques in the presence of very limited data. We present results of applying HOCC to two different network data sets, first for detection and classification of anomalies in a border gateway protocol dataset and second for building models of users from network file system calls to perform masquerade detection. The precision of our system has been shown to be 30% better than the standard Naive Bayes technique for masquerade detection. These results indicate that HOCC can successfully model a variety of network events and can be applied to solve difficult problems in security using the general framework proposed.
Keywords :
Bayes methods; learning (artificial intelligence); pattern classification; security of data; Naive Bayes technique; anomaly classification; anomaly detection; border gateway protocol dataset; higher order collective classifier; machine learning techniques; masquerade detection; network events classification; network events detection; network file system; Computer science; Data security; Event detection; File systems; Machine learning; Phase detection; Predictive models; Problem-solving; Protocols; Robustness;
Conference_Titel :
Intelligence and Security Informatics, 2009. ISI '09. IEEE International Conference on
Conference_Location :
Dallas, TX
Print_ISBN :
978-1-4244-4171-6
Electronic_ISBN :
978-1-4244-4173-0
DOI :
10.1109/ISI.2009.5137283