Efficient masquerade detection using SVM based on common command frequency in sliding windows

Cited 2 time in webofscience Cited 0 time in scopus
  • Hit : 493
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorKim, HSko
dc.contributor.authorCha, Sungdeokko
dc.date.accessioned2013-03-03T17:29:21Z-
dc.date.available2013-03-03T17:29:21Z-
dc.date.created2012-02-06-
dc.date.created2012-02-06-
dc.date.issued2004-11-
dc.identifier.citationIEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, v.E87D, no.11, pp.2446 - 2452-
dc.identifier.issn0916-8532-
dc.identifier.urihttp://hdl.handle.net/10203/79690-
dc.description.abstractMasqueraders who impersonate other users pose serious threat to computer security. Unfortunately, firewalls or misuse-based intrusion detection systems are generally ineffective in detecting masqueraders. Anomaly detection techniques have been proposed as a complementary approach to overcome such limitations. However, they are not accurate enough in detection, and the rate of false alarm is too high for the technique to be applied in practice. For example, recent empirical studies on masquerade detection using UNIX commands found the accuracy to be below 70%. In this research, we per-formed a comparative study to investigate the effectiveness of SVM (Support Vector Machine) technique using the same data set and configuration reported in the previous experiments. In order to improve accuracy of masquerade detection, we used command frequencies in sliding windows as feature sets. In addition, we chose to ignore commands commonly used by all the users and introduce the concept of voting engine. Though still imperfect, we were able to improve the accuracy of masquerade detection to 80.1% and 94.8%, whereas previous studies reported accuracy of 69.3% and 62.8% in the same configurations. This study convincingly demonstrates that SVM is useful as an anomaly detection technique and that there are several advantages SVM offers as a tool to detect masqueraders.-
dc.languageEnglish-
dc.publisherIEICE-INST ELECTRONICS INFORMATION COMMUNICATIONS ENG-
dc.titleEfficient masquerade detection using SVM based on common command frequency in sliding windows-
dc.typeArticle-
dc.identifier.wosid000225210500002-
dc.type.rimsART-
dc.citation.volumeE87D-
dc.citation.issue11-
dc.citation.beginningpage2446-
dc.citation.endingpage2452-
dc.citation.publicationnameIEICE TRANSACTIONS ON INFORMATION AND SYSTEMS-
dc.contributor.nonIdAuthorKim, HS-
dc.type.journalArticleArticle-
dc.subject.keywordAuthorintrusion detection-
dc.subject.keywordAuthormasquerade detection-
dc.subject.keywordAuthoranomaly detection-
dc.subject.keywordAuthormachine learning-
dc.subject.keywordAuthorSVM (Support Vector Machine)-
dc.subject.keywordAuthoruser command-
Appears in Collection
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 2 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0