Cost-sensitive active learning algorithm for intrusion detection

Long Jun,Yin Jian-Ping,Zhu En,Zhao Wen-Tao
DOI: https://doi.org/10.3321/j.issn:0469-5097.2008.05.009
2008-01-01
Abstract:Intrusion detection systems (IDS) protect the computer system by providing alerts which might be caused by malicious attacks. Machine Learning methods were introduced into intrusion detection to automatically improve the performance by using history data. Yet high quality data requires heavy labor of experts or expensive monitoring process. Meanwhile, different types of misclassification result in different costs and IDS should minimize a nonuniform misclassification cost. In the paper, we aim to reduce the burden of labeling data for constructing the intrusion detection classifier with the least misclassification cost. We proposed a novel active cost-sensitive learning method ACS (active cost-sensitive sampling) for intrusion detection using the technologies of active learning and cost-sensitive learning. The proposed method uses a popular cost-sensitive learning method Metacost as the base classifier and a sampling criterion of the largest misclassification cost. The ACS method modifies the construction and updating process of version space according to the cost-sensitive environment, thus it can converge to the target function with the lowest misclassification cost quickly. The results of the experiments on intrusion detection datasets of KDDCUP 99 show that the proposed method is effective.
What problem does this paper attempt to address?