Dynamic combination of multiple host-based anomaly detectors with broader detection coverage and fewer false alerts

Zonghua Zhang, Hong Shen

研究成果: Conference article同行評審

摘要

To achieve broader detection coverage with fewer false alarms, a POMDP-based anomaly detection model combining several sate-of-the-art host-based anomaly detectors is proposed in this paper. An optimal combinatorial manner is expected to be discovered through a policy-gradient reinforcement learning algorithm, based on the independent actions of those detectors, and the behavior of the proposed model can be adjusted through a global reward signal to adapt to various system situations. A primarily experiment with some comparative studies are carried out to validate its performance.

原文English
頁(從 - 到)989-996
頁數8
期刊Lecture Notes in Computer Science
3421
發行號II
DOIs
出版狀態Published - 2005
對外發佈
事件Networking - ICN 2005 - Reunion Island, France
持續時間: 17 4月 200521 4月 2005

指紋

深入研究「Dynamic combination of multiple host-based anomaly detectors with broader detection coverage and fewer false alerts」主題。共同形成了獨特的指紋。

引用此