Use of K-Nearest Neighbor classifier for intrusion detection

Use of K-Nearest Neighbor classifier for intrusion detection
复制标题

DOI:
10.1016/s0167-4048(02)00514-x
复制
发表时间:
2002-01-01
影响因子:
5.6
通讯作者:
Vemuri, VR
Vemuri, VR
中科院分区:
计算机科学3区
文献类型:
--
作者:
Liao, YH;Vemuri, VR

文献摘要

被引文献

相似文献

提出了一种基于k近邻(KNN)分类器的程序行为分类方法。反过来,程序行为由系统调用的频率表示。每个系统调用被视为一个单词,每个程序执行过程中的系统调用集合被视为一个文档。然后使用KNN分类器对这些文档进行分类,KNN分类器是文本分类中流行的方法。与那些试图用短的系统调用序列来描述程序行为并生成单独的程序配置文件的方法相比,这种方法似乎提供了一些计算优势。用1998年的DARPA BSM审计数据进行的初步实验表明,KNN分类器能够有效地检测入侵攻击,并获得较低的误检率。
A new approach, based on the k-Nearest Neighbor (kNN) classifier, is used to classify program behavior as normal or intrusive. Program behavior, in turn, is represented by frequencies of system calls. Each system call is treated as a word and the collection of system calls over each program execution as a document. These documents are then classified using kNN classifier, a popular method in text categorization. This method seems to offer some computational advantages over those that seek to characterize program behavior with short sequences of system calls and generate individual program profiles. Preliminary experiments with 1998 DARPA BSM audit data show that the kNN classifier can effectively detect intrusive attacks and achieve a low false Positive rate.