Title :
Effective Virtual Machine Monitor Intrusion Detection Using Feature Selection on Highly Imbalanced Data
Author :
Alshawabkeh, Malak ; Moffie, Micha ; Azmandian, Fatemeh ; Aslam, Javed A. ; Dy, Jennifer ; Kaeli, David
Author_Institution :
Dept. of Electr. & Comput. Eng., Northeastern Univ., Boston, MA, USA
Abstract :
Virtualization is becoming an increasingly popular service hosting platform. Recently, intrusion detection systems (IDSs) which utilize virtualization have been introduced. One particular challenge present in current virtualization-based IDS systems is considered in this paper. IDS systems are commonly faced with high-dimensionality imbalanced data. Improved feature selection methods are needed to achieve more accurate detection when presented with imbalanced data. These methods must select the right set of features which will lead to a lower number of false alarms and higher correct detection rates. In this paper we propose a new Boosting-based feature selection that evaluates the relative importance of individual features using the fractional absolute confidence that Boosting produces. Our approach accounts for the sample distributions by optimizing for the area under the Receive Operating Characteristic (ROC) curve (i.e., Area Under the Curve(AUC)). Empirical results on different commercial virtual appliances and malwares indicate that proper input feature selection is key if we want an effective virtualization-based IDS that is lightweight, efficient and effective.
Keywords :
feature extraction; security of data; virtual machines; ROC curve; boosting-based feature selection; high-dimensionality imbalanced data; intrusion detection system; receive operating characteristic curve; virtual machine monitoring; virtualization-based IDS system; Bit error rate; Boosting; Data mining; Feature extraction; Malware; Servers; Virtual machining; Virtual machine monitoring; boosting; feature selection; imbalanced data; intrusion detection;
Conference_Titel :
Machine Learning and Applications (ICMLA), 2010 Ninth International Conference on
Conference_Location :
Washington, DC
Print_ISBN :
978-1-4244-9211-4
DOI :
10.1109/ICMLA.2010.127