A network security audit system based on support vector data description algorithm
Guyu Hu · Caai Transactions on Intelligent Systems · 2007
Security audit, which is the basis of intrusion detection, provides the necessary data for intrusion detection analysis. In traditional security audit and intrusion detection system, the characteristics of an attack need to be defined by experts for the system to be able to successfully identify anomalous activities. Due to the difficulty in predicting attack data, in most cases administrators only get normal sequences of system calls. In this paper, a security audit system based on SVDD algorithm was designed to resolve the one-class problem in anomalous activity detection. All activities deviating from normal patterns were classified as potential intrusions. In experiments using the international standard data set MIT LPR, the one-class classifier achieved a 100% detection rate and a zero false alarm rate for sequences of system calls based on a small training dataset. The proposed algorithms can be trained for anomalous activity detection simply by using normal samples and the algorithm also enables the security audit system to detect new types of anomalous behavior.