Title :
A hybrid approach to the profile creation and intrusion detection
Author :
Marin, Jack ; Ragsdale, Daniel ; Sirdu, J.
Author_Institution :
Inf. Technol. & Oper. Center, US Mil. Acad., West Point, NY, USA
Abstract :
Anomaly detection involves characterizing the behaviors of individuals or systems and recognizing behavior that is outside the norm. This paper describes some preliminary results concerning the robustness and generalization capabilities of machine learning methods in creating user profiles based on the selection and subsequent classification of command line arguments. We base our method on the belief that legitimate users can be classified into categories based on the percentage of commands they use in a specified period. The hybrid approach we employ begins with the application of expert rules to reduce the dimensionality of the data, followed by an initial clustering of the data and subsequent refinement of the cluster locations using a competitive network called Learning Vector Quantization. Since Learning Vector Quantization is a nearest neighbor classifier, and new record presented to the network that lies outside a specified distance is classified as a masquerader. Thus, this system does not require anomalous records to be included in the training set
Keywords :
authorisation; knowledge based systems; learning (artificial intelligence); pattern classification; security of data; Learning Vector Quantization; anomaly detection; command line arguments; competitive network; expert rules; hybrid approach; intrusion detection; machine learning methods; masquerader; nearest neighbor classifier; profile creation; user profiles; Authorization; Character recognition; Frequency; Information technology; Intrusion detection; Learning systems; Lifting equipment; Nearest neighbor searches; Robustness; Vector quantization;
Conference_Titel :
DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
Conference_Location :
Anaheim, CA
Print_ISBN :
0-7695-1212-7
DOI :
10.1109/DISCEX.2001.932193