An SVM An SVM-
- based Masquerade Detection
based Masquerade Detection Method with Online Update Using Method with Online Update Using Co Co-
- occurrence Matrix
- ccurrence Matrix
An SVM- -based Masquerade Detection based Masquerade Detection An - - PowerPoint PPT Presentation
An SVM- -based Masquerade Detection based Masquerade Detection An SVM Method with Online Update Using Method with Online Update Using Co- -occurrence Matrix occurrence Matrix Co Liangwen Chen, Masayoshi Chen, Masayoshi Aritsugi Aritsugi
cd ls less emacs gcc gdb mkdir cp 0 0 0 0 0 0 0 0 0 3 0 3 1 1 0 0 0 0 0 0 0 0 0 0 0 4 0 1 3 3 0 0 0 4 0 2 1 3 0 0 0 5 0 2 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 cd ls less emacs gcc gdb mkdir cp
High freq. Low freq. Commands in Legitimate training data All other commands Commands in Legitimate training data Low freq. High freq.
emacs ls gcc gdb cd less mkdir cp 2 4 3 3 0 0 0 0 3 3 1 1 0 0 0 0 2 4 1 3 0 0 0 0 2 5 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 emacs ls gcc gdb cd less mkdir cp All other commands
Training data Co-occ. Matrx. Gen. Co-occ. Matrx. Co-occ. Matrx. Feature vectr. Feature vectr. SVM training model results
New sequence
0.04 0.04 s s Detection cost Detection cost 10.03 10.03 s s 6.90 6.90 s s 7.04 7.04 s s 3.36 3.36 s s SVM SVM training training costs costs 107.30 107.30 s s 89.65 89.65 s s 59.53 59.53 s s 43.86 43.86 s s Update costs Update costs 0.93 0.93 0.91 0.91 0.90 0.90 0.89 0.89 ROC Score ROC Score 72.74% 72.74% 68% 68% 69% 69% 68% 68% Hit Rate Hit Rate 3% 3% 5% 5% 6% 6% 8% 8% False Positive False Positive 50 50 blks blks. . (25000) (25000) 40 40 blks blks. . (20000) (20000) 30 30 blks blks. . (15000) (15000) 20 20 blks blks. . (10000) (10000)
# trained # trained commands commands
0.04 0.04 s s D e t e c t i
c
t D e t e c t i
c
t 0.27 0.27 s s 0.22 0.22 s s 0.18 0.18 s s 0.17 0.17 s s SVM SVM t r a i n i n g t r a i n i n g c
t s c
t s 2.15 2.15 s s 1.79 1.79 s s 1.53 1.53 s s 0.88 0.88 s s U p d a t e c
t s U p d a t e c
t s 0.88 0.88 0.87 0.87 0.86 0.86 0.85 0.85 ROC Score ROC Score 62.77 62.77 % % 61% 61% 64% 64% 68% 68% Hit Rate Hit Rate 6% 6% 7% 7% 8% 8% 12% 12% False Positive False Positive 50 50 blks blks. . (5000) (5000) 40 40 blks blks. . (4000) (4000) 30 30 blks blks. . (3000) (3000) 20 20 blks blks. . (2000) (2000) # t r a i n e d # t r a i n e d c
m a n d s c
m a n d s