DocumentCode
831729
Title
Data Fusion and Cost Minimization for Intrusion Detection
Author
Parikh, Devi ; Chen, Tsuhan
Author_Institution
Dept. of Electr. & Comput. Eng., Carnegie Mellon Univ., Pittsburgh, PA
Volume
3
Issue
3
fYear
2008
Firstpage
381
Lastpage
389
Abstract
Statistical pattern recognition techniques have recently been shown to provide a finer balance between misdetections and false alarms than the more conventional intrusion detection approaches, namely misuse detection and anomaly detection. A variety of classical machine learning and pattern recognition algorithms has been applied to intrusion detection with varying levels of success. We make two observations about intrusion detection. One is that intrusion detection is significantly more effective by using multiple sources of information in an intelligent way, which is precisely what human experts rely on. Second, different errors in intrusion detection have different costs associated with them-a simplified example being that a false alarm may be more expensive than a misdetection and, hence, the true objective function to be minimized is the cost of errors and not the error rate itself. We present a pattern recognition approach that addresses both of these issues. It utilizes an ensemble of a classifiers approach to intelligently combine information from multiple sources and is explicitly tuned toward minimizing the cost of the errors as opposed to the error rate itself. The information fusion approach dLEARNIN alone is shown to achieve state-of-the-art performances better than those reported in the literature so far, and the cost minimization strategy dCMS further reduces the cost with a significant margin.
Keywords
cryptography; learning (artificial intelligence); pattern recognition; sensor fusion; anomaly detection; cost minimization; data fusion; information fusion approach; intrusion detection; machine learning algorithms; misuse detection; pattern recognition algorithms; Computer networks; Cost function; Error analysis; Humans; Information resources; Intrusion detection; Learning systems; Machine learning; Machine learning algorithms; Pattern recognition; Cost minimization; dCMS; dLEARNIN; data fusion; pattern recognition for intrusion detection;
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2008.928539
Filename
4598829
Link To Document