One-Class Training for Masquerade Detection

One-Class Training for Masquerade Detection
复制标题

DOI:
10.7916/d89c7455
复制
发表时间:
2003
期刊:
--
影响因子:
--
通讯作者:
Ke Wang;S. Stolfo
Ke Wang;S. Stolfo
中科院分区:
其他
文献类型:
--
作者:
Ke Wang;S. Stolfo

文献摘要

被引文献

相似文献

我们扩展了以前的研究伪装检测使用UNIX命令发出的用户作为审计源。以前使用多类训练的研究需要从多个用户那里收集数据,为每个用户训练自我和非自我的特定配置文件。单类训练使用仅代表一个用户的数据。我们应用一类朴素贝叶斯使用多变量伯努利模型和多项式模型,和一类SVM算法。实验结果表明,该任务的单类训练和多类训练一样有效,具有收集更少数据和更有效训练的巨大实际优势。使用二进制特征的单类SVM在单类训练算法中表现最好。
We extend prior research on masquerade detection using UNIX commands issued by users as the audit source. Previous studies using multi-class training requires gathering data from multiple users to train specific profiles of self and non-self for each user. Oneclass training uses data representative of only one user. We apply one-class Naive Bayes using both the multivariate Bernoulli model and the Multinomial model, and the one-class SVM algorithm. The result shows that oneclass training for this task works as well as multi-class training, with the great practical advantages of collecting much less data and more efficient training. One-class SVM using binary features performs best among the oneclass training algorithms.