Factor analysis based anomaly detection
Factor analysis based anomaly detection
复制标题
基于因子分析的异常检测
DOI:
10.1109/smcsia.2003.1232408
复制
发表时间:
2003
期刊:
影响因子:
--
通讯作者:
Jing Zhang
中科院分区:
文献类型:
--
作者:
Ningning Wu;Jing Zhang
We propose a novel anomaly detection algorithm based on factor analysis and Mahalanobis distance. Factor analysis is used to uncover the latent structure (dimensions) of a set of variables. It reduces attribute space from a larger number of variables to a smaller number of factors. The Mahalanobis distance is used to determine the "similarity" of a set of values from an "unknown" sample to a set of values measured from a collection of "known" samples. Combined with factor analysis, Mahalanobis distance is extended to examine whether a given vector is an outlier from a model identified by "factors" based on factor analysis. We present a factor analysis-based network anomaly detection algorithm and apply it to DARPA intrusion detection evaluation data. The experimental results show that the proposed algorithm is able to detect network intrusions with relatively low false alarms.