异常检测
水准点(测量)
计算机科学
入侵检测系统
概率逻辑
异常(物理)
标杆管理
公制(单位)
利用
探测器
数据挖掘
基于异常的入侵检测系统
人工智能
算法
工程类
物理
地质学
电信
计算机安全
凝聚态物理
业务
营销
运营管理
大地测量学
作者
Roy A. Maxion,Kymie Tan
标识
DOI:10.1109/icdsn.2000.857599
摘要
Anomaly detection is a key element of intrusion detection and other detection systems in which perturbations of normal behavior suggest the presence of intentionally or unintentionally induced attacks, faults, defects, etc. Because most anomaly detectors are based on probabilistic algorithms that exploit the intrinsic structure (or regularity) embedded in data logs, a fundamental question is whether or not such structure influences detection performance. If detector performance is indeed a function of environmental regularity, it would be critical to match detectors to environmental characteristics. In intrusion-detection settings, however, this is not done, possibly because such characteristics are not easily ascertained. This paper introduces a metric for characterizing structure in data environments, and tests the hypothesis that intrinsic structure influences probabilistic detection. In a series of experiments, an anomaly detection algorithm was applied to a benchmark suite of 165 carefully calibrated, anomaly-injected data sets of varying structure. The results showed performance differences of as much as an order of magnitude, indicating that current approaches to anomaly detection may not be universally dependable.
科研通智能强力驱动
Strongly Powered by AbleSci AI