TY - GEN
T1 - A reference based analysis framework for analyzing system call traces
AU - Chandola, Varun
AU - Boriah, Shyam
AU - Kumar, Vipin
PY - 2010
Y1 - 2010
N2 - Reference based analysis (RBA) is a novel data mining tool for exploring a test data set with respect to a reference data set. The power of RBA lies in it ability to transform any complex data type, such as symbolic sequences and multi-variate categorical data instances, into a multivariate continuous representation. The transformed representation not only allows visualization of the complex data, which cannot be otherwise visualized in its original form, but also allows enhanced anomaly detection in the transformed feature space. We demonstrate the application of the RBA framework in analyzing system call traces and show how the transformation results in improved intrusion detection performance over state of art data mining based intrusion detection methods developed for system call traces.
AB - Reference based analysis (RBA) is a novel data mining tool for exploring a test data set with respect to a reference data set. The power of RBA lies in it ability to transform any complex data type, such as symbolic sequences and multi-variate categorical data instances, into a multivariate continuous representation. The transformed representation not only allows visualization of the complex data, which cannot be otherwise visualized in its original form, but also allows enhanced anomaly detection in the transformed feature space. We demonstrate the application of the RBA framework in analyzing system call traces and show how the transformation results in improved intrusion detection performance over state of art data mining based intrusion detection methods developed for system call traces.
KW - anomaly detection
KW - intrusion detection
KW - reference based analysis
UR - https://www.scopus.com/pages/publications/78349263114
UR - https://www.scopus.com/pages/publications/78349263114#tab=citedBy
U2 - 10.1145/1852666.1852703
DO - 10.1145/1852666.1852703
M3 - Conference contribution
AN - SCOPUS:78349263114
SN - 9781450300179
T3 - ACM International Conference Proceeding Series
BT - 6th Annual Cyber Security and Information Intelligence Research Workshop
T2 - 6th Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies, CSIIRW10
Y2 - 21 April 2010 through 23 April 2010
ER -