|
|
|
Attack Characterization and Intrusion Detection using an Ensemble of Self-Organizing MapsLori DeLoozeThe 7th IEEE Information Assurance Workshop (IAWorkshop 2006)West Point, New York, USA, June 21-23, 2006
AbstractSelf-Organized Maps (SOM) use an unsupervised learning technique to independently organize a set of input patterns into various classes. In this paper, we use an ensemble of SOMs to identify computer attacks and characterize them appropriately using the major classes of computer attacks (Denial of Service, Probe, User-to-Root and Remote-to-Local). The procedure produces a set of confidence levels for each connection as a way to describe the connection’s behavior.
|
|