Open Access. Powered by Scholars. Published by Universities.®

Physical Sciences and Mathematics Commons

Open Access. Powered by Scholars. Published by Universities.®

Air Force Institute of Technology

Series

Clustering

Discipline
Publication Year

Articles 1 - 2 of 2

Full-Text Articles in Physical Sciences and Mathematics

The Importance Of Generalizability To Anomaly Detection, Gilbert L. Peterson, Brent T. Mcbride Mar 2008

The Importance Of Generalizability To Anomaly Detection, Gilbert L. Peterson, Brent T. Mcbride

Faculty Publications

In security-related areas there is concern over novel “zero-day” attacks that penetrate system defenses and wreak havoc. The best methods for countering these threats are recognizing “nonself” as in an Artificial Immune System or recognizing “self” through clustering. For either case, the concern remains that something that appears similar to self could be missed. Given this situation, one could incorrectly assume that a preference for a tighter fit to self over generalizability is important for false positive reduction in this type of learning problem. This article confirms that in anomaly detection as in other forms of classification a tight fit, …


A Comparison Of Generalizability For Anomaly Detection, Gilbert L. Peterson, Robert F. Mills, Brent T. Mcbride, Wesley T. Allred Aug 2005

A Comparison Of Generalizability For Anomaly Detection, Gilbert L. Peterson, Robert F. Mills, Brent T. Mcbride, Wesley T. Allred

Faculty Publications

In security-related areas there is concern over the novel “zeroday” attack that penetrates system defenses and wreaks havoc. The best methods for countering these threats are recognizing “non-self” as in an Artificial Immune System or recognizing “self” through clustering. For either case, the concern remains that something that looks similar to self could be missed. Given this situation one could logically assume that a tighter fit to self rather than generalizability is important for false positive reduction in this type of learning problem. This article shows that a tight fit, although important, does not supersede having some model generality. This …