A General Framework for Adaptive Anomaly Detection with Evolving Connectionist Systems
نویسندگان
چکیده
A new adaptive anomaly detection framework, based on the use of unsupervised evolving connectionist systems, is proposed to address the issue of concept drift. It is designed to adapt to normal behavior changes while still recognizing anomalies. The evolving connectionist systems learn a subject’s behavior in an online, adaptive fashion without a priori knowledge of the underlying data distributions. Experiments with the KDD Cup 1999 network data and the Windows NT user profiling data show that our adaptive anomaly detection systems, based on Fuzzy Adaptive Resonance Theory (ART) and Evolving Fuzzy Neural Networks (EFuNN), can significantly reduce the false alarm rate while the attack detection rate remains high.
منابع مشابه
Adaptive anomaly detection with evolving connectionist systems
Anomaly detection holds great potential for detecting previously unknown attacks. In order to be effective in a practical environment, anomaly detection systems have to be capable of online learning and handling concept drift. In this paper, a new adaptive anomaly detection framework, based on the use of unsupervised evolving connectionist systems, is proposed to address these issues. It is des...
متن کاملEvolving Connectionist Systems Evolving Connectionist and Fuzzy-Connectionist Systems for On-line Adaptive Decision Making and Control
The paper contains a discussion material and preliminary experimental results on a new approach to building on-line, adaptive decision making and control systems. This approach is called evolving connectionist systems (ECOS). ECOS evolve through incremental, on-line learning. They can accommodate any new input data, including new features, new classes, etc. New connections and new neurons are c...
متن کاملChapter 7. Evolving Connectionist and Fuzzy - Connectionist Systems: Theory and Applications for Adaptive, On-line Intelligent Systems
The paper introduces one paradigm of neuro-fuzzy techniques and an approach to building on-line, adaptive intelligent systems. This approach is called evolving connectionist systems (ECOS). ECOS evolve through incremental, online learning, both supervised and unsupervised. They can accommodate new input data, including new features, new classes, etc. New connections and new neurons are created ...
متن کاملBrain-like Functions in Evolving Connectionist Systems for On-line, Knowledge-Based Learning
The paper discusses some biological principles of the human brain that would be useful to implement in intelligent information systems (IS). These principles are used to formulate seven major requirements to the current and the future IS. These requirements are met in a new connectionist architecture called evolving connectionist systems (ECOS). ECOS are designed to facilitate building on-line,...
متن کاملADAPTIVE ORDERED WEIGHTED AVERAGING FOR ANOMALY DETECTION IN CLUSTER-BASED MOBILE AD HOC NETWORKS
In this paper, an anomaly detection method in cluster-based mobile ad hoc networks with ad hoc on demand distance vector (AODV) routing protocol is proposed. In the method, the required features for describing the normal behavior of AODV are defined via step by step analysis of AODV and independent of any attack. In order to learn the normal behavior of AODV, a fuzzy averaging method is used fo...
متن کامل