A Cascading Intrusion Detection Framework Using OCSVM and SSVM

碩士 === 國立臺灣科技大學 === 資訊工程系 === 93 === Information system assurance is one of the most concerned issues by researches, government organizations and many commercial firms. In order to assure the integrity of computer systems, more and more defense techniques are being brought out such as firewall, anti...

Full description

Bibliographic Details
Main Authors: Lin-Kuei Yang, 楊琳貴
Other Authors: Yuh-Jye Lee
Format: Others
Language:en_US
Published: 2005
Online Access:http://ndltd.ncl.edu.tw/handle/88843230264429602307
id ndltd-TW-093NTUST392032
record_format oai_dc
spelling ndltd-TW-093NTUST3920322016-06-08T04:13:17Z http://ndltd.ncl.edu.tw/handle/88843230264429602307 A Cascading Intrusion Detection Framework Using OCSVM and SSVM 應用單類別支撐向量機與平滑支撐向量機的階層式入侵偵測架構 Lin-Kuei Yang 楊琳貴 碩士 國立臺灣科技大學 資訊工程系 93 Information system assurance is one of the most concerned issues by researches, government organizations and many commercial firms. In order to assure the integrity of computer systems, more and more defense techniques are being brought out such as firewall, anti-virus software, intrusion detection system, etc. Intrusion detection system is a novel defense technique which can determine if a computer network or server has experienced an unauthorized intrusion. In this thesis, we proposed a cascading intrusion detection framework in which we use one class support vector machine (OCSVM) and smooth support vector machine (SSVM) as the core techniques. Generally, OCSVM is used to capture normal behavior in anomaly intrusion detection. Here we exploit OCSVM to profile normal behavior as well as all kinds of intrusion activities respectively. Due to the success of support vector machines in the applications of binary classification, we apply a variant version of support vector machines, SSVM, to discriminate between normal and intrusive activities. We combine OCSVM with SSVM to constitute a sophisticated structure to detect intrusions efficiently. In order to deal with the massive dataset in our training process, chunking technique is introduced in this thesis. By testing our system on 1999 KDD contest dataset, our system performs better than 1999 KDD winner in either intrusion detection or intrusion diagnostic based on the 1999 KDD scoring measure. Besides, our system also has better prediction rates toward DoS and r2l connections than other well-known algorithms. Yuh-Jye Lee 李育杰 2005 學位論文 ; thesis 51 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立臺灣科技大學 === 資訊工程系 === 93 === Information system assurance is one of the most concerned issues by researches, government organizations and many commercial firms. In order to assure the integrity of computer systems, more and more defense techniques are being brought out such as firewall, anti-virus software, intrusion detection system, etc. Intrusion detection system is a novel defense technique which can determine if a computer network or server has experienced an unauthorized intrusion. In this thesis, we proposed a cascading intrusion detection framework in which we use one class support vector machine (OCSVM) and smooth support vector machine (SSVM) as the core techniques. Generally, OCSVM is used to capture normal behavior in anomaly intrusion detection. Here we exploit OCSVM to profile normal behavior as well as all kinds of intrusion activities respectively. Due to the success of support vector machines in the applications of binary classification, we apply a variant version of support vector machines, SSVM, to discriminate between normal and intrusive activities. We combine OCSVM with SSVM to constitute a sophisticated structure to detect intrusions efficiently. In order to deal with the massive dataset in our training process, chunking technique is introduced in this thesis. By testing our system on 1999 KDD contest dataset, our system performs better than 1999 KDD winner in either intrusion detection or intrusion diagnostic based on the 1999 KDD scoring measure. Besides, our system also has better prediction rates toward DoS and r2l connections than other well-known algorithms.
author2 Yuh-Jye Lee
author_facet Yuh-Jye Lee
Lin-Kuei Yang
楊琳貴
author Lin-Kuei Yang
楊琳貴
spellingShingle Lin-Kuei Yang
楊琳貴
A Cascading Intrusion Detection Framework Using OCSVM and SSVM
author_sort Lin-Kuei Yang
title A Cascading Intrusion Detection Framework Using OCSVM and SSVM
title_short A Cascading Intrusion Detection Framework Using OCSVM and SSVM
title_full A Cascading Intrusion Detection Framework Using OCSVM and SSVM
title_fullStr A Cascading Intrusion Detection Framework Using OCSVM and SSVM
title_full_unstemmed A Cascading Intrusion Detection Framework Using OCSVM and SSVM
title_sort cascading intrusion detection framework using ocsvm and ssvm
publishDate 2005
url http://ndltd.ncl.edu.tw/handle/88843230264429602307
work_keys_str_mv AT linkueiyang acascadingintrusiondetectionframeworkusingocsvmandssvm
AT yánglínguì acascadingintrusiondetectionframeworkusingocsvmandssvm
AT linkueiyang yīngyòngdānlèibiézhīchēngxiàngliàngjīyǔpínghuázhīchēngxiàngliàngjīdejiēcéngshìrùqīnzhēncèjiàgòu
AT yánglínguì yīngyòngdānlèibiézhīchēngxiàngliàngjīyǔpínghuázhīchēngxiàngliàngjīdejiēcéngshìrùqīnzhēncèjiàgòu
AT linkueiyang cascadingintrusiondetectionframeworkusingocsvmandssvm
AT yánglínguì cascadingintrusiondetectionframeworkusingocsvmandssvm
_version_ 1718296966393233408