Useful anomaly intrusion detection method using multiple-instance learning

Ye Du,Youyan Guo,YongZhong He,Ying Cai
2008-01-01
Journal of Computational Information Systems
Abstract:With the ever increasing sophistication of attacking techniques, intrusion detection has been paid more attention. A novel anomaly intrusion detection method working at the level of system processes is proposed in this paper. The multiple-instance learning receives growing interests in the machine learning research field, which concerns the problem of classifying a bag of instances. By looking upon each short system call sequence as an instance and each observable symbol as a bag that contains some instances, the task of detecting abnormal behaviors can be mapped as multiple-instance learning. Thus the related techniques can be used to solve the problem, and here k-nearest neighbor with a new kernel is created as the core algorithm. Experiments using UNM data sets and comparison with other methods proved the validity of this method.
What problem does this paper attempt to address?