An anomaly detection model for information acquisition

Fei Wang,Yuwen Qian,Yuewei Dai,ZhiQuan Wang
2010-01-01
Journal of Information and Computational Science
Abstract:In view of low-level information acquisition of anomaly detection, an anomaly detection model for information acquisition is proposed. First, Support Vector Machine (SVM) is applied to detect abnormal network connections; second, a packet filtering scheme is used for classification and matching, which is performed by an ensemble of one-class SVM(OC-SVM) classifier, after that, unknown intrusions are obtained and as input of clustering part, from which the anomalous connections are classified further and get their valid information. Lastly, the experiments are done based on kddcup99 dataset. Its result indicates that the proposed model can get more information about the anomalous connections effectively with relative high detection rate with low false rate. Copyright © 2010 Binary Information Press.
What problem does this paper attempt to address?