首页> 外文会议>International Symposium on Recent Advances in Intrusion Detection(RAID 2006); 20060920-22; Hamburg(DE) >Anomaly Detector Performance Evaluation Using a Parameterized Environment
【24h】

Anomaly Detector Performance Evaluation Using a Parameterized Environment

机译:使用参数化环境的异常检测器性能评估

获取原文
获取原文并翻译 | 示例

摘要

Over the years, intrusion detection has matured into a field replete with anomaly detectors of various types. These detectors are tasked with detecting computer-based attacks, insider threats, worms and more. Their abundance easily prompts the question - is anomaly detection improving in efficacy and reliability? Current evaluation strategies may provide answers; however, they suffer from problems. For example, they produce results that are only valid within the evaluation data set and they provide very little by way of diagnostic information to tune detector performance in a principled manner.rnThis paper studies the problem of acquiring reliable performance results for an anomaly detector. Aspects of a data environment that will affect detector performance, such as the frequency distribution of data elements, are identified, characterized and used to construct a synthetic data environment to assess a frequency-based anomaly detector. In a series of experiments that systematically maps out the detector's performance, areas of detection weaknesses are exposed, and strengths are identified. Finally, the extensibility of the lessons learned in the synthetic environment are observed using real-world data.
机译:多年来,入侵检测已经发展成为一个充满各种类型的异常检测器的领域。这些检测器的任务是检测基于计算机的攻击,内部威胁,蠕虫等。它们的丰富性很容易引发问题-异常检测是否可以提高功效和可靠性?当前的评估策略可能会提供答案;但是,他们遇到了问题。例如,它们产生的结果仅在评估数据集中有效,并且它们提供的诊断信息很少以有原则的方式来调整检测器的性能。本文研究了获取异常检测器可靠性能结果的问题。识别,表征和影响将影响检测器性能的数据环境方面,例如数据元素的频率分布,并用于构建综合数据环境以评估基于频率的异常检测器。在一系列系统地绘制出探测器性能的实验中,发现了探测薄弱环节,并确定了优势。最后,使用实际数据观察在综合环境中学习到的课程的可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号