Evaluating Host-Based Anomaly Detection Systems: Application of the Frequency-Based Algorithms to ADFA-LD

Evaluating Host-Based Anomaly Detection Systems: Application of the Frequency-Based Algorithms to ADFA-LD
复制标题

DOI:
10.1007/978-3-319-11698-3_44
复制
发表时间:
2014-10
期刊:
--
影响因子:
--
通讯作者:
Miao Xie;Jiankun Hu;Xinghuo Yu;Elizabeth Chang
Miao Xie;Jiankun Hu;Xinghuo Yu;Elizabeth Chang
中科院分区:
其他
文献类型:
--
作者:
Miao Xie;Jiankun Hu;Xinghuo Yu;Elizabeth Chang

文献摘要

被引文献

相似文献

ADFA Linux数据集(ADFA-LD)是最近发布的,用于取代基于主机的异常检测领域的现有基准数据集,这些基准数据集已经失去了与现代计算机系统的大部分相关性。ADFA-LD由从当代Linux本地服务器收集的数千个系统调用跟踪组成,涉及六种最新的网络攻击类型。在此之前,我们已经对ADFA-LD进行了初步的分析,结果表明,与基于短序列的算法相比,基于频率的算法可以以更低的计算代价实现,同时获得了可以接受的性能。在本文中,我们进一步挖掘基于频率的算法的潜力,试图降低频率向量的维度,并确定最优距离函数。两种典型的基于频率的算法,即k-最近邻(KNN)和k-均值聚类(KMC),被用来验证该算法的有效性和效率。
ADFA Linux data set (ADFA-LD) is released recently for substituting the existing benchmark data sets in the area of host-based anomaly detection which have lost most of their relevance to modern computer systems. ADFA-LD is composed of thousands of system call traces collected from a contemporary Linux local server, with six types of up-to-date cyber attack involved. Previously, we have conducted a preliminary analysis of ADFA-LD, and shown that the frequency-based algorithms can be realised at a cheaper computational cost in contrast with the short sequence-based algorithms, while achieving an acceptable performance. In this paper, we further exploit the potential of the frequency-based algorithms, in attempts to reduce the dimension of the frequency vectors and identify the optimal distance functions. Two typical frequency-based algorithms, i.e., k-nearest neighbour (kNN) and k-means clustering (kMC), are applied to validate the effectiveness and efficiency.