MétaCan
Menu
Back to cohort
Record W2103414007 · doi:10.1109/tsmcc.2010.2048428

Toward Credible Evaluation of Anomaly-Based Intrusion-Detection Methods

2010· article· en· W2103414007 on OpenAlexaff
Mahbod Tavallaee, Natalia Stakhanova, Ali A. Ghorbani

Bibliographic record

VenueIEEE Transactions on Systems Man and Cybernetics Part C (Applications and Reviews) · 2010
Typearticle
Languageen
FieldComputer Science
TopicNetwork Security and Intrusion Detection
Canadian institutionsUniversity of New Brunswick
Fundersnot available
KeywordsIntrusion detection systemAnomaly detectionAnomaly-based intrusion detection systemVariety (cybernetics)Constant false alarm rateComputer scienceAnomaly (physics)Data miningField (mathematics)Data scienceMainstreamComputer securityArtificial intelligenceMathematics

Abstract

fetched live from OpenAlex

Since the first introduction of anomaly-based intrusion detection to the research community in 1987, the field has grown tremendously. A variety of methods and techniques introducing new capabilities in detecting novel attacks were developed. Most of these techniques report a high detection rate of 98% at the low false alarm rate of 1%. In spite of the anomaly-based approach's appeal, the industry generally favors signature-based detection for mainstream implementation of intrusion-detection systems. While a variety of anomaly-detection techniques have been proposed, adequate comparison of these methods' strengths and limitations that can lead to potential commercial application is difficult. Since the validity of experimental research in academic computer science, in general, is questionable, it is plausible to assume that research in anomaly detection shares the above problem. The concerns about the validity of these methods may partially explain why anomaly-based intrusion-detection methods are not adopted by industry. To investigate this issue, we review the current state of the experimental practice in the area of anomaly-based intrusion detection and survey 276 studies in this area published during the period of 2000-2008. We summarize our observations and identify the common pitfalls among surveyed works.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.090
metaresearch head score (Gemma)0.321
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesMetaresearch
Consensus categoriesnone
DomainCandidate signal: Evaluation · Consensus signal: none
Study designCandidate signal: Theoretical or conceptual · Consensus signal: none
GenreCandidate signal: Methods · Consensus signal: Methods
Teacher disagreement score0.910
Threshold uncertainty score0.474

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0900.321
Meta-epidemiology (narrow)0.0020.001
Meta-epidemiology (broad)0.0020.001
Bibliometrics0.0090.004
Science and technology studies0.0010.003
Scholarly communication0.0060.008
Open science0.0050.003
Research integrity0.0030.003
Insufficient payload (model declined to judge)0.0010.001

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.049
GPT teacher head0.319
Teacher spread0.270 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

Study designTheoretical or conceptual
DomainEvaluation
GenreMethods

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations280
Published2010
Admission routes1
Has abstractyes

Explore more

Same venueIEEE Transactions on Systems Man and Cybernetics Part C (Applications and Reviews)Same topicNetwork Security and Intrusion DetectionFrench-language works237,207