A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection

被引:1480
作者
Buczak, Anna L. [1 ]
Guven, Erhan [1 ]
机构
[1] Johns Hopkins Univ, Appl Phys Lab, Johns Hopkins Rd, Laurel, MD 20723 USA
来源
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS | 2016年 / 18卷 / 02期
关键词
Cyber analytics; data mining; machine learning; SYSTEMS; MODEL;
D O I
10.1109/COMST.2015.2494502
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This survey paper describes a focused literature survey of machine learning (ML) and data mining (DM) methods for cyber analytics in support of intrusion detection. Short tutorial descriptions of each ML/DM method are provided. Based on the number of citations or the relevance of an emerging method, papers representing each method were identified, read, and summarized. Because data are so important in ML/DM approaches, some well-known cyber data sets used in ML/DM are described. The complexity of ML/DM algorithms is addressed, discussion of challenges for using ML/DM for cyber security is presented, and some recommendations on when to use a given method are provided.
引用
收藏
页码:1153 / 1176
页数:24
相关论文
共 110 条
[11]  
[Anonymous], P 20 C NEUR INF PROC
[12]  
[Anonymous], 2000, R Language Definition
[13]  
[Anonymous], 2004, P 2004 ACM S APPL CO, DOI DOI 10.1145/967900.967989
[14]  
[Anonymous], 1995, SELF ORG MAP
[15]   Characterizing network traffic by means of the NETMINE framework [J].
Apiletti, Daniele ;
Baralis, Elena ;
Cerquitelli, Tania ;
D'Elia, Vincenzo .
COMPUTER NETWORKS, 2009, 53 (06) :774-789
[16]   HMMPayl: An intrusion detection system based on Hidden Markov Models [J].
Ariu, Davide ;
Tronci, Roberto ;
Giacinto, Giorgio .
COMPUTERS & SECURITY, 2011, 30 (04) :221-241
[17]  
Årnes A, 2006, LECT NOTES COMPUT SC, V4219, P145
[18]   Evolution strategies – A comprehensive introduction [J].
Hans-Georg Beyer ;
Hans-Paul Schwefel .
Natural Computing, 2002, 1 (1) :3-52
[19]  
BARALIS E, 2008, GEN ITEMSET DISCOVER
[20]   AN INEQUALITY WITH APPLICATIONS TO STATISTICAL ESTIMATION FOR PROBABILISTIC FUNCTIONS OF MARKOV PROCESSES AND TO A MODEL FOR ECOLOGY [J].
BAUM, LE ;
EAGON, JA .
BULLETIN OF THE AMERICAN MATHEMATICAL SOCIETY, 1967, 73 (03) :360-&