Anomaly Detection in Computer Networks Using Dissimilarity-Based One-Class Classifiers

Jun Ma,GuanZhong Dai
DOI: https://doi.org/10.1109/ISDA.2008.129
2008-01-01
Abstract:Anomaly detection in computer networks tries to detect traffic deviation from the normal model. Traditionally, feature-based one-class classifiers are the main components of anomaly detection systems. The performance of this anomaly detection system largely depends on the result of the feature selection. Dissimilarity representations describe an object by its dissimilarities to a set of target class. The dissimilarity-based one-class classifiers (DBOCCs) are constructed on dissimilarity representations. Redundancy and relativity of the features cast little influence on the performance of DBOCCs. This paper proposes anomaly detection using DBOCCs with unsupervised learning approach. Several combinations of DBOCCs scheme have also been used. The experimental results on KDDCUP'99 dataset shows that DBOCCs can achieve high detection rate and low false positive without large degeneration in performance as traditional feature-based classifiers suffered when different feature subsets have been used.
What problem does this paper attempt to address?