Use of K-Nearest Neighbor classifier for intrusion detection

被引:469
|
作者
Liao, YH [1 ]
Vemuri, VR [1 ]
机构
[1] Univ Calif Davis, Dept Comp Sci, Davis, CA 95616 USA
关键词
k-Nearest Neighbor classifier; intrusion detection; system calls; text categorization; program profile;
D O I
10.1016/S0167-4048(02)00514-X
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A new approach, based on the k-Nearest Neighbor (kNN) classifier, is used to classify program behavior as normal or intrusive. Program behavior, in turn, is represented by frequencies of system calls. Each system call is treated as a word and the collection of system calls over each program execution as a document. These documents are then classified using kNN classifier, a popular method in text categorization. This method seems to offer some computational advantages over those that seek to characterize program behavior with short sequences of system calls and generate individual program profiles. Preliminary experiments with 1998 DARPA BSM audit data show that the kNN classifier can effectively detect intrusive attacks and achieve a low false Positive rate.
引用
收藏
页码:439 / 448
页数:10
相关论文
共 50 条
  • [21] Consistency of the k-Nearest Neighbor Classifier for Spatially Dependent Data
    Younso, Ahmad
    Kanaya, Ziad
    Azhari, Nour
    [J]. COMMUNICATIONS IN MATHEMATICS AND STATISTICS, 2023, 11 (03) : 503 - 518
  • [22] A parameter independent fuzzy weighted k-Nearest neighbor classifier
    Biswas, Nimagna
    Chakraborty, Saurajit
    Mullick, Sankha Subhra
    Das, Swagatam
    [J]. PATTERN RECOGNITION LETTERS, 2018, 101 : 80 - 87
  • [23] A fuzzy K-nearest neighbor classifier to deal with imperfect data
    Jose M. Cadenas
    M. Carmen Garrido
    Raquel Martínez
    Enrique Muñoz
    Piero P. Bonissone
    [J]. Soft Computing, 2018, 22 : 3313 - 3330
  • [24] An Algorithm of Incremental Bayesian Classifier Based on K-Nearest Neighbor
    Wang, Dong
    Xiong, Shi-huan
    [J]. MEMS, NANO AND SMART SYSTEMS, PTS 1-6, 2012, 403-408 : 1455 - 1459
  • [25] K-Nearest Neighbor Classifier for Uncertain Data in Feature Space
    Lim, Sung-Yeon
    Ko, Changwan
    Jeong, Young-Seon
    Baek, Jaeseung
    [J]. INDUSTRIAL ENGINEERING AND MANAGEMENT SYSTEMS, 2023, 22 (04): : 414 - 421
  • [26] Boosting the distance estimation -: Application to the K-Nearest Neighbor Classifier
    Amores, J
    Sebe, N
    Radeva, P
    [J]. PATTERN RECOGNITION LETTERS, 2006, 27 (03) : 201 - 209
  • [27] Adaptation of the fuzzy k-nearest neighbor classifier for manufacturing automation
    Tobin, KW
    Gleason, SS
    Karnowski, TP
    [J]. MACHINE VISION APPLICATIONS IN INDUSTRIAL INSPECTION VI, 1998, 3306 : 122 - 130
  • [28] A MODIFIED K-NEAREST NEIGHBOR CLASSIFIER TO DEAL WITH UNBALANCED CLASSES
    AlSukker, Akram
    Al-Ani, Ahmed
    Atiya, Amir
    [J]. IJCCI 2009: PROCEEDINGS OF THE INTERNATIONAL JOINT CONFERENCE ON COMPUTATIONAL INTELLIGENCE, 2009, : 408 - +
  • [29] Fake News Detection Using LDA Topic Modelling and K-Nearest Neighbor Classifier
    Casillo, Mario
    Colace, Francesco
    Gupta, Brij B.
    Santaniello, Domenico
    Valentino, Carmine
    [J]. COMPUTATIONAL DATA AND SOCIAL NETWORKS, CSONET 2021, 2021, 13116 : 330 - 339
  • [30] A fuzzy K-nearest neighbor classifier to deal with imperfect data
    Cadenas, Jose M.
    Carmen Garrido, M.
    Martinez, Raquel
    Munoz, Enrique
    Bonissone, Piero P.
    [J]. SOFT COMPUTING, 2018, 22 (10) : 3313 - 3330