TY - JOUR
T1 - Application of online-training SVMs for real-time intrusion detection with different considerations
AU - Zhang, Zonghua
AU - Shen, Hong
N1 - Funding Information:
This research is conducted as a program for the ‘Fostering Talent in Emergent Research Fields’ in Special Coordination Funds for Promoting Science and Technology by Ministry of Education, Culture, Sports, Science and Technology.
PY - 2005/7/18
Y1 - 2005/7/18
N2 - As intrusion detection essentially can be formulated as a binary classification problem, it thus can be solved by an effective classification technique - Support Vector Machine (SVM). Additionally, some text processing techniques can also be employed for intrusion detection, based on the characterization of the frequencies of the system calls executed by the privileged programs. Based on the intersection of these two research domains, i.e. pattern recognition and text categorization, and breaking the strong traditional assumption that training data for intrusion detectors are readily available with high quality in batch, the conventional SVM, Robust SVM and one-class SVM have been modified respectively based on the idea from Online SVM in this paper, and their performances are compared with that of the original algorithms. After elaborate theoretical analysis, concrete experiments with 1998 DARPA BSM data set collected at MIT's Lincoln Labs are carried out. These experiments verify that the modified SVMs can be trained online and the results outperform the original ones with fewer support vectors (SVs) and less training time without decreasing detection accuracy. Both of these achievements could significantly benefit an effective online intrusion detection system.
AB - As intrusion detection essentially can be formulated as a binary classification problem, it thus can be solved by an effective classification technique - Support Vector Machine (SVM). Additionally, some text processing techniques can also be employed for intrusion detection, based on the characterization of the frequencies of the system calls executed by the privileged programs. Based on the intersection of these two research domains, i.e. pattern recognition and text categorization, and breaking the strong traditional assumption that training data for intrusion detectors are readily available with high quality in batch, the conventional SVM, Robust SVM and one-class SVM have been modified respectively based on the idea from Online SVM in this paper, and their performances are compared with that of the original algorithms. After elaborate theoretical analysis, concrete experiments with 1998 DARPA BSM data set collected at MIT's Lincoln Labs are carried out. These experiments verify that the modified SVMs can be trained online and the results outperform the original ones with fewer support vectors (SVs) and less training time without decreasing detection accuracy. Both of these achievements could significantly benefit an effective online intrusion detection system.
KW - Anomaly detection
KW - Computer security
KW - Intrusion detection
KW - Support vector machines
KW - Text categorization
UR - http://www.scopus.com/inward/record.url?scp=21844433474&partnerID=8YFLogxK
U2 - 10.1016/j.comcom.2005.01.014
DO - 10.1016/j.comcom.2005.01.014
M3 - Article
AN - SCOPUS:21844433474
SN - 0140-3664
VL - 28
SP - 1428
EP - 1442
JO - Computer Communications
JF - Computer Communications
IS - 12
ER -