• DocumentCode
    831729
  • Title

    Data Fusion and Cost Minimization for Intrusion Detection

  • Author

    Parikh, Devi ; Chen, Tsuhan

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Carnegie Mellon Univ., Pittsburgh, PA
  • Volume
    3
  • Issue
    3
  • fYear
    2008
  • Firstpage
    381
  • Lastpage
    389
  • Abstract
    Statistical pattern recognition techniques have recently been shown to provide a finer balance between misdetections and false alarms than the more conventional intrusion detection approaches, namely misuse detection and anomaly detection. A variety of classical machine learning and pattern recognition algorithms has been applied to intrusion detection with varying levels of success. We make two observations about intrusion detection. One is that intrusion detection is significantly more effective by using multiple sources of information in an intelligent way, which is precisely what human experts rely on. Second, different errors in intrusion detection have different costs associated with them-a simplified example being that a false alarm may be more expensive than a misdetection and, hence, the true objective function to be minimized is the cost of errors and not the error rate itself. We present a pattern recognition approach that addresses both of these issues. It utilizes an ensemble of a classifiers approach to intelligently combine information from multiple sources and is explicitly tuned toward minimizing the cost of the errors as opposed to the error rate itself. The information fusion approach dLEARNIN alone is shown to achieve state-of-the-art performances better than those reported in the literature so far, and the cost minimization strategy dCMS further reduces the cost with a significant margin.
  • Keywords
    cryptography; learning (artificial intelligence); pattern recognition; sensor fusion; anomaly detection; cost minimization; data fusion; information fusion approach; intrusion detection; machine learning algorithms; misuse detection; pattern recognition algorithms; Computer networks; Cost function; Error analysis; Humans; Information resources; Intrusion detection; Learning systems; Machine learning; Machine learning algorithms; Pattern recognition; Cost minimization; dCMS; dLEARNIN; data fusion; pattern recognition for intrusion detection;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2008.928539
  • Filename
    4598829