An outlier ensemble for unsupervised anomaly detection in honeypots data

被引:5
|
作者
Boukela, Lynda [1 ]
Zhang, Gongxuan [1 ]
Bouzefrane, Samia [2 ]
Zhou, Junlong [1 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Comp Sci & Engn, 200 Xiaolingwei St, Nanjing 210094, Peoples R China
[2] Conservatoire Natl Arts & Metiers, CEDRIC Lab, Paris, France
基金
中国国家自然科学基金;
关键词
Outlier ensembles; network security; anomaly detection; honeypots; FRAMEWORK;
D O I
10.3233/IDA-194656
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Nowadays, computers, as well as smart devices, are connected through communication networks making them more vulnerable to attacks. Honeypots are proposed as deception tools but usually used as part of a proactive defense strategy. Hence, this article demonstrates how honeypots data can be analyzed in an active defense strategy. Furthermore, anomaly detection based on unsupervised machine learning techniques allows to build autonomous systems and to detect unknown anomalies without the need for prior knowledge. However, the unsupervised techniques applied for honeypots data analysis do not value the advantages of these tools' data, particularly the high probability that they include a large number of previously unseen anomalies with unexpected and diverse patterns. Therefore, in the present work, the aim is to improve the unsupervised anomaly detection in honeypots data by varying the data feature subset and the parameterization of the anomaly detection algorithm. To this purpose, an outlier ensemble with LOF (Local Outlier Factor) as a base algorithm is proposed. The ensemble outperforms existing solutions as depicted in the experiments where a detection rate higher than 92% is achieved.
引用
收藏
页码:743 / 758
页数:16
相关论文
共 50 条
  • [1] Ensemble Algorithms for Unsupervised Anomaly Detection
    Zhao, Zhiruo
    Mehrotra, Kishan G.
    Mohan, Chilukuri K.
    CURRENT APPROACHES IN APPLIED ARTIFICIAL INTELLIGENCE, 2015, 9101 : 514 - 525
  • [2] Anomaly Based Network Intrusion Detection with Unsupervised Outlier Detection
    Zhang, Jiong
    Zulkernine, Mohammad
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2388 - 2393
  • [3] UNSUPERVISED ANOMALY DETECTION FOR TIME SERIES WITH OUTLIER EXPOSURE
    Feng, Jiaming
    Huang, Zheng
    Guo, Jie
    Qiu, Weidong
    33RD INTERNATIONAL CONFERENCE ON SCIENTIFIC AND STATISTICAL DATABASE MANAGEMENT (SSDBM 2021), 2020, : 1 - 12
  • [4] Unsupervised outlier detection in multidimensional data
    Atiq ur Rehman
    Samir Brahim Belhaouari
    Journal of Big Data, 8
  • [5] Unsupervised outlier detection in multidimensional data
    Ur Rehman, Atiq
    Belhaouari, Samir Brahim
    JOURNAL OF BIG DATA, 2021, 8 (01)
  • [6] Sequential Ensemble Method for Unsupervised Anomaly Detection
    Huy Van Nguyen
    Trung Thanh Nguyen
    Quang Uy Nguyen
    2017 9TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE 2017), 2017, : 71 - 76
  • [7] Time Series Analysis: Unsupervised Anomaly Detection Beyond Outlier Detection
    Landauer, Max
    Wurzenberger, Markus
    Skopik, Florian
    Settanni, Giuseppe
    Filzmoser, Peter
    INFORMATION SECURITY PRACTICE AND EXPERIENCE (ISPEC 2018), 2018, 11125 : 19 - 36
  • [8] ENAD: An Ensemble Framework for Unsupervised Network Anomaly Detection
    Liao, Jingyi
    Teo, Sin G.
    Kundu, Partha Pratim
    Tram Truong-Huu
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 81 - 88
  • [9] Outlier and anomaly pattern detection on data streams
    Cheong Hee Park
    The Journal of Supercomputing, 2019, 75 : 6118 - 6128
  • [10] Outlier and anomaly pattern detection on data streams
    Park, Cheong Hee
    JOURNAL OF SUPERCOMPUTING, 2019, 75 (09): : 6118 - 6128