DocumentCode
2315537
Title
A Higher Order Collective Classifier for detecting and classifying network events
Author
Menon, Vikas ; Pottenger, William M.
Author_Institution
Dept. of Comput. Sci., Rutgers Univ., New Brunswick, NJ, USA
fYear
2009
fDate
8-11 June 2009
Firstpage
125
Lastpage
130
Abstract
Labeled data is scarce. Most statistical machine learning techniques rely on the availability of a large labeled corpus for building robust models for prediction and classification. In this paper we present a Higher Order Collective Classifier (HOCC) based on higher order learning, a statistical machine learning technique that leverages latent information present in co-occurrences of items across records. These techniques violate the IID assumption that underlies most statistical machine learning techniques and have in prior work outperformed first order techniques in the presence of very limited data. We present results of applying HOCC to two different network data sets, first for detection and classification of anomalies in a border gateway protocol dataset and second for building models of users from network file system calls to perform masquerade detection. The precision of our system has been shown to be 30% better than the standard Naive Bayes technique for masquerade detection. These results indicate that HOCC can successfully model a variety of network events and can be applied to solve difficult problems in security using the general framework proposed.
Keywords
Bayes methods; learning (artificial intelligence); pattern classification; security of data; Naive Bayes technique; anomaly classification; anomaly detection; border gateway protocol dataset; higher order collective classifier; machine learning techniques; masquerade detection; network events classification; network events detection; network file system; Computer science; Data security; Event detection; File systems; Machine learning; Phase detection; Predictive models; Problem-solving; Protocols; Robustness;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligence and Security Informatics, 2009. ISI '09. IEEE International Conference on
Conference_Location
Dallas, TX
Print_ISBN
978-1-4244-4171-6
Electronic_ISBN
978-1-4244-4173-0
Type
conf
DOI
10.1109/ISI.2009.5137283
Filename
5137283
Link To Document