Use of K-Nearest Neighbor classifier for intrusion detection

被引:469
|
作者
Liao, YH [1 ]
Vemuri, VR [1 ]
机构
[1] Univ Calif Davis, Dept Comp Sci, Davis, CA 95616 USA
关键词
k-Nearest Neighbor classifier; intrusion detection; system calls; text categorization; program profile;
D O I
10.1016/S0167-4048(02)00514-X
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A new approach, based on the k-Nearest Neighbor (kNN) classifier, is used to classify program behavior as normal or intrusive. Program behavior, in turn, is represented by frequencies of system calls. Each system call is treated as a word and the collection of system calls over each program execution as a document. These documents are then classified using kNN classifier, a popular method in text categorization. This method seems to offer some computational advantages over those that seek to characterize program behavior with short sequences of system calls and generate individual program profiles. Preliminary experiments with 1998 DARPA BSM audit data show that the kNN classifier can effectively detect intrusive attacks and achieve a low false Positive rate.
引用
收藏
页码:439 / 448
页数:10
相关论文
共 50 条
  • [1] Intrusion Detection Using k-Nearest Neighbor
    Govindarajan, M.
    Chandrasekaran, R. M.
    [J]. FIRST INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING 2009 (ICAC 2009), 2009, : 13 - +
  • [2] Intrusion Detection System for IP Multimedia Subsystem Using K-Nearest Neighbor classifier
    Farooqi, Ashfaq Hussain
    Munir, Ali
    [J]. INMIC: 2008 INTERNATIONAL MULTITOPIC CONFERENCE, 2008, : 423 - 428
  • [3] Hybrid k-Nearest Neighbor Classifier
    Yu, Zhiwen
    Chen, Hantao
    Liu, Jiming
    You, Jane
    Leung, Hareton
    Han, Guoqiang
    [J]. IEEE TRANSACTIONS ON CYBERNETICS, 2016, 46 (06) : 1263 - 1275
  • [4] A fall detection system using k-nearest neighbor classifier
    Liu, Chien-Liang
    Lee, Chia-Hoang
    Lin, Ping-Min
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2010, 37 (10) : 7174 - 7181
  • [5] Evidential Editing K-Nearest Neighbor Classifier
    Jiao, Lianmeng
    Denoeux, Thierry
    Pan, Quan
    [J]. SYMBOLIC AND QUANTITATIVE APPROACHES TO REASONING WITH UNCERTAINTY, ECSQARU 2015, 2015, 9161 : 461 - 471
  • [6] Optimization Strategies for the k-Nearest Neighbor Classifier
    Yepdjio Nkouanga H.
    Vajda S.
    [J]. SN Computer Science, 4 (1)
  • [7] Detection and Localization of Myocardial Infarction using K-nearest Neighbor Classifier
    Muhammad Arif
    Ijaz A. Malagore
    Fayyaz A. Afsar
    [J]. Journal of Medical Systems, 2012, 36 : 279 - 289
  • [8] Detection and Localization of Myocardial Infarction using K-nearest Neighbor Classifier
    Arif, Muhammad
    Malagore, Ijaz A.
    Afsar, Fayyaz A.
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (01) : 279 - 289
  • [9] Arrhythmia Detection from Heartbeat Using k-Nearest Neighbor Classifier
    Park, Juyoung
    Lee, Kuyeon
    Kang, Kyungtae
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE (BIBM), 2013,
  • [10] K-Nearest Neighbor and Boundary Cutting Algorithm for Intrusion Detection System
    Mulak, Punam
    Gaikwad, D. P.
    Talhar, N. R.
    [J]. INFORMATION SYSTEMS DESIGN AND INTELLIGENT APPLICATIONS, VOL 2, INDIA 2016, 2016, 434 : 269 - 278