Anomaly Detection Based on SVM

Tan Xiaobin · 2003

A key component of computer security techniques, intrusion detection has gotten more and more attention. An overview of our research on anomaly detection is presented, which uses system call traces as audit data. It is focused on issues related to constructing a support vector machine(SVM) for detecting intrusion or misuse of computers, and introduce an improved algorithm for SVM. A method for the pretreatment of audit data is given, and the choice of kernel function is discussed. To improve performance, the sequential minimal optimization(SMO) as the update algorithm for the SVM is used. This method is not only useful in theory, but also can be used in practice to monitor the computer system in real time.

Read the paper · More papers on PaperTik