DocumentCode
607990
Title
Learning Anomalies in IDSs by Means of Multivariate Finite Mixture Models
Author
Greggio, N.
Author_Institution
ARTS Lab., Pontedera, Italy
fYear
2013
fDate
25-28 March 2013
Firstpage
251
Lastpage
258
Abstract
In this work a fast method for the unsupervised fitting of a set of data by means of Gaussian mixtures has been studied and developed. It allows to implement applications to Information Security, with major on anomaly detection Intrusion Detection Systems (IDSs). Its key feature is the online selection of the number of mixture components together with the fitting parameter of each component. With many components the description is accurate. However, the computational burden increases as well. The best compromise between the description accuracy and the computational complexity is given by a derivation of the Minimum Message Length (MML) information criterion. The normal network behavior is assumed to be interpreted by the cluster with the highest covariance matrix, while the other smaller components are considered representing anomalies. We tested our technique with the well known KDD99 Cup data set, in order to clearly compare our findings with the other state of the art methods. Our results show the effectiveness of this algorithm in finding anomalies within normal network traffic, and encourage for further improvements.
Keywords
computational complexity; covariance matrices; security of data; Gaussian mixtures; IDS; anomaly detection; computational complexity; covariance matrix; information security; intrusion detection system; minimum message length information criterion; multivariate finite mixture model; normal network behavior; normal network traffic; online selection; unsupervised fitting; Binary trees; Clustering algorithms; Covariance matrices; Gaussian mixture model; Image segmentation; Intrusion detection; Solid modeling; Anomaly detection IDS; KDD99 Cup; Machine Learning; Self-Adapting Expectation Maximization; Unsupervised Clustering;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications (AINA), 2013 IEEE 27th International Conference on
Conference_Location
Barcelona
ISSN
1550-445X
Print_ISBN
978-1-4673-5550-6
Electronic_ISBN
1550-445X
Type
conf
DOI
10.1109/AINA.2013.151
Filename
6531763
Link To Document