Investigating hidden Markov models capabilities in anomaly detection

Investigating hidden Markov models capabilities in anomaly detection
复制标题

DOI:
10.1145/1167350.1167387
复制
发表时间:
2005-03
期刊:
--
影响因子:
--
通讯作者:
S. Joshi;V. Phoha
S. Joshi;V. Phoha
中科院分区:
其他
文献类型:
--
作者:
S. Joshi;V. Phoha

文献摘要

被引文献

相似文献

基于隐马尔可夫模型(HMM)的应用在各个领域都很常见,但将HMM用于异常检测仍处于起步阶段。本文利用隐马尔可夫模型将网络流量分为攻击流量和正常流量两类。本文的主要目标是建立一个异常检测系统,一个能够区分网络流量正常和异常行为的预测模型。在训练阶段,特别注意初始化和模型选择问题,这使得训练阶段特别有效。对于训练HMM,使用了KDD CUP1999数据集中存在的全部特征中的12.195的特征(41个特征中的5个特征)。在KDD CUP 1999数据集上的测试结果表明,该系统能够按照用于训练HMM的特征数量的比例对网络流量进行分类。我们正在扩大我们在更大数据集上的工作,以建立一个异常检测系统。
Hidden Markov Model (HMM) based applications are common in various areas, but the incorporation of HMM's for anomaly detection is still in its infancy. This paper aims at classifying the TCP network traffic as an attack or normal using HMM. The paper's main objective is to build an anomaly detection system, a predictive model capable of discriminating between normal and abnormal behavior of network traffic. In the training phase, special attention is given to the initialization and model selection issues, which makes the training phase particularly effective. For training HMM, 12.195% features out of the total features (5 features out of 41 features) present in the KDD Cup 1999 data set are used. Result of tests on the KDD Cup 1999 data set shows that the proposed system is able to classify network traffic in proportion to the number of features used for training HMM. We are extending our work on a larger data set for building an anomaly detection system.