跳至主導覽 跳至搜尋 跳過主要內容

Constructing a multilayered boundary to defend against intrusive anomalies

  • Zonghua Zhang
  • , Hong Shen

研究成果: Article同行評審

摘要

We propose a model for constructing a multilayered boundary in an information system to defend against intrusive anomalies by correlating a number of parametric anomaly detectors. The model formulation is based on two observations. First, anomaly detectors differ in their detection coverage or blind spots. Second, operating environments of the anomaly detectors reveal different information about system anomalies. The correlation among observation-specific anomaly detectors is first formulated as a Partially Observable Markov Decision Process, and then a policy-gradient reinforcement learning algorithm is developed for an optimal cooperation search, with the practical objectives being broader overall detection coverage and fewer false alerts. A host-based experimental scenario is developed to illustrate the principle of the model and to demonstrate its performance.

原文English
頁(從 - 到)490-499
頁數10
期刊IEICE Transactions on Information and Systems
E90-D
發行號2
DOIs
出版狀態Published - 2月 2007
對外發佈

指紋

深入研究「Constructing a multilayered boundary to defend against intrusive anomalies」主題。共同形成了獨特的指紋。

引用此