ADAM 论文

2001ACM SIGMOD Record引用 240
Network Security and Intrusion DetectionSpam and Phishing DetectionAdvanced Malware Detection Techniques

详细信息

发表期刊/会议
ACM SIGMOD Record
发表日期
2001-12-01
发表年份
2001

关键词

Network Security and Intrusion DetectionSpam and Phishing DetectionAdvanced Malware Detection Techniques

摘要

Intrusion detection systems have traditionally been based on the characterization of an attack and the tracking of the activity on the system to see if it matches that characterization. Recently, new intrusion detection systems based on data mining are making their appearance in the field. This paper describes the design and experiences with the ADAM (Audit Data Analysis and Mining) system, which we use as a testbed to study how useful data mining techniques can be in intrusion detection.