Factor analysis based anomaly detection

Factor analysis based anomaly detection
复制标题

基于因子分析的异常检测

DOI:
10.1109/smcsia.2003.1232408
复制
发表时间:
2003
期刊:
IEEE Systems, Man and Cybernetics SocietyInformation Assurance Workshop, 2003.
影响因子:
--
通讯作者:
Jing Zhang
Jing Zhang
中科院分区:
--
文献类型:
--
作者:
Ningning Wu;Jing Zhang

文献摘要

被引文献

相似文献

提出了一种基于因子分析和马氏距离的异常检测算法。因子分析用于揭示一组变量的潜在结构(维度)。它将属性空间从大量的变量减少到更少的因子。Mahalanobis距离用于确定来自“未知”样本的一组值与从“已知”样本的集合测量的一组值的“相似性”。结合因子分析,将马氏距离扩展到基于因子分析的模型中,以检验给定向量是否是由“因子”标识的模型的离群值。提出了一种基于因子分析的网络异常检测算法,并将其应用于DARPA入侵检测评估数据。实验结果表明,该算法能够检测到网络入侵与相对较低的虚警。
We propose a novel anomaly detection algorithm based on factor analysis and Mahalanobis distance. Factor analysis is used to uncover the latent structure (dimensions) of a set of variables. It reduces attribute space from a larger number of variables to a smaller number of factors. The Mahalanobis distance is used to determine the "similarity" of a set of values from an "unknown" sample to a set of values measured from a collection of "known" samples. Combined with factor analysis, Mahalanobis distance is extended to examine whether a given vector is an outlier from a model identified by "factors" based on factor analysis. We present a factor analysis-based network anomaly detection algorithm and apply it to DARPA intrusion detection evaluation data. The experimental results show that the proposed algorithm is able to detect network intrusions with relatively low false alarms.