Biased Support Vector Machines and Kernel Methods for Intrusion Detection

K. Yendrapalli, Srinivas Mukkamala, Andrew H. Sung, Bernardete Ribeiro · 2007

Abstract – This paper describes results concerning the robustness and generalization capabilities of kernel methods in detecting intrusions using network audit trails. We use traditional support vector machines (SVM), biased support vector machine (BSVM) and leave-one-out model selection for support vector machines (looms) for model selection. We also evaluate the impact of kernel type and parameter values on the accuracy of a support vector machine (SVM) performing intrusion classification. Through a variety of comparative experiments, it is found that SVM performs the best for detecting Normal and User to Super User, BSVM performs the best for Denial of Service attacks, and looms based on BSVM performs the best for Probe and Remote to Local. We show that classification accuracy varies with the kernel type and the parameter values; thus, with appropriately chosen parameter values, intrusions can be detected by SVMs with higher accuracy and lower rates of false alarms. Index Terms—Intrusion detection, Model selection, Kernel machines, Support vector machines

Read the paper · More papers on PaperTik