Anomaly Detection Method for Noisy Training Data
Zhou Jingli · Journal of Chinese Computer Systems · 2006
Generally, in anomaly detection,Object's normal behavior model is built from training data without intrusions.But this kind of training data is not easy to get:First,if the data is produced by synthesis,it will be different from real data of target environment;if the data is obtained from target environment,it is difficult to ensure the data does not contain intrusions.In this paper,by exploiting the different probability distributions of intrusion and normal traffic in training data, a new network-based anomaly intrusion detection method is proposed.Compared with previous schemes,empirical experiments showing that with training data containing intrusions,the proposed method has higher detection rates.At the same time,for clean training data,the proposed method shows compared performance with previous schemes.