Learning rules for anomaly detection of hostile network traffic

Matthew V. Mahoney, Philip K. Chan · 2003

We introduce an algorithm called LERAD that learns rules for finding rare events in nominal time-series data with long range dependencies. We use LERAD to find anomalies in network packets and TCP sessions to detect novel intrusions. We evaluated LERAD on the 1999 DARPA/Lincoln Laboratory intrusion detection evaluation data set and on traffic collected in a university departmental server environment.

Read the paper · More papers on PaperTik