arrow
Return

CorrCorr: A feature selection method for multivariate correlation network anomaly detection techniques

delete2019-06-01
delete52
PRE
AI
F
Florian Gottwalt *
E
Elizabeth Chang
T
Tharam S. Dillon
DOI:10.1016/j.cose.2019.02.008delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Recent research on network intrusion detection has focused on correlation-based techniques, which allow one to adapt to continuously changing environments such as the Internet of Things. Despite it being common practice for network intrusion detection to utilise feature selection techniques to enhance performance, correlation-based techniques have rarely been applied to them. This is mainly due the fact that traditional feature selection methods are not tailored to multivariate correlation techniques and new methods are required. To address this gap, we are introducing CorrCorr, a feature selection method for multivariate correlation-based network anomaly detection systems. Evaluated on the UNSW-NB15 and NSL-KDD intrusion detection dataset, CorrCorr consistently outperformed the original features as well as features selected with a Principal Component Analysis (PCA) and a Pearson class label correlation. We also analysed the UNSW-NB15 dataset on feature correlations and have identified several weaknesses. (C) 2019 Elsevier Ltd. All rights reserved.
Keywords:
Feature selection
Multivariate correlation
Correlation anomaly detection
Intrusion detection
Network anomaly detection
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

A
australian defense force academy
Scholars:
609
Papers: 640
Citations: 0