יובל אלוביץ

אקדמי בכיר

An Overview of IDS Using Anomaly Detection

Intrusion detection is the process of monitoring and analyzing the events occurring in a computer system in order to detect signs of security problems. The problem of intrusion detection can be solved using anomaly detection techniques. For instance, one is given a set of connection data belonging to different classes (normal activity, different attacks) and the aim is to construct a classifier that accurately classifies new unlabeled connections data. Clustering methods can be used to detect anomaly in data which might implies intrusion of a new type. This chapter gives a critical summary of anomaly detection research for intrusion detection. This chapter surveys a list of research projects that apply anomaly detection techniques to intrusion detection. Finally some directions for research are given.

שפת פרסום אנגלית
דפים 384-394
כרך 1
סטטוס פרסום פורסם - 01.01.2009

ASJC Scopus subject areas

General Economics, Econometrics and Finance
General Business, Management and Accounting
General Computer Science
קבצים וקישורים אחרים
Link to publication in Scopus