Anomaly Detection System Based on Principal Component Analysis and Support Vector Machine

Li Zhanchun,Li Zhitang,Liu Bin
DOI: https://doi.org/10.1007/bf02831871
2006-01-01
Abstract:This article presents an anomaly detection system based on principal component analysis (PCA) and support vector machine (SVM). The system first creates a profile defining a normal behavior by frequency-based scheme, and then compares the similarity of a current behavior with the created profile to decide whether the input instance is normal or anomaly. In order to avoid overfitting and reduce the computational burden, normal behavior principal features are extracted by the PCA method. SVM is used to distinguish normal or anomaly for user behavior after training procedure has been completed by learning. In the experiments for performance evaluation the system achieved a correct detection rate equal to 92.2% and a false detection rate equal to 2.8%.
What problem does this paper attempt to address?