Skip to main navigation Skip to search Skip to main content

Usage behavior profiling for anomaly detection using vector quantization

  • Jun Zheng*
  • , Mingzeng Hu
  • , Hongli Zhang
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In network security community, anomaly detection is the research center as one of the important intrusion detection approaches. Constructing the usage behavior profile is the first important step in anomaly detection. In this paper, using the self-organizing maps (SOM), we propose to design the vector quantization (VQ) framework to build usage profile for anomaly detection. After the feature attribute extraction, the network traffic flow is translated into the feature vector style. And then, the network traffic usage behavior profile can be represented by the VQ codebook from which the behaviour deviation can be measured quantitatively. Via the intrusion detection benchmark data of "DARPA Intrusion Detection Evaluation" in experiments, it is shown that the network attacks are detected with high detection rates and low false alarms.

Original languageEnglish
Title of host publicationProceedings of the IASTED International Conference on Communication Systems and Applications, as part of the Fifth IASTED Int. Multi-Conference on Wireless and Optical Communications, CSA 2005
EditorsA.O. Fapojuwo
Pages107-112
Number of pages6
StatePublished - 2005
Externally publishedYes
EventIASTED International Conference on Communication Systems and Applications, as part of the Fifth IASTED International Multi-Conference on Wireless and Optical Communications, CSA 2005 - Banff, AB, Canada
Duration: 19 Jul 200521 Jul 2005

Publication series

NameProceedings of the IASTED International Conference on Communication Systems and Applications, as part of the Fifth IASTED Int. Multi-Conference on Wireless and Optical Communications, CSA 2005

Conference

ConferenceIASTED International Conference on Communication Systems and Applications, as part of the Fifth IASTED International Multi-Conference on Wireless and Optical Communications, CSA 2005
Country/TerritoryCanada
CityBanff, AB
Period19/07/0521/07/05

Keywords

  • Anomaly detection
  • Codebook
  • Self-organizing map
  • Usage behavior profile
  • Vector quantization

Fingerprint

Dive into the research topics of 'Usage behavior profiling for anomaly detection using vector quantization'. Together they form a unique fingerprint.

Cite this