OCPAD: One class Naive Bayes classifier for payload based anomaly detection

作者:

Highlights:

• OCPAD: Multinomial Bayesian one class classifier for anomalous payload detection.

• A tree to store probability ranges of ngrams found in non malicious payloads.

• OCPAD has high Detection Rate and low False Positives.

• Theoretical and experimental comparison with other methods.

摘要

•OCPAD: Multinomial Bayesian one class classifier for anomalous payload detection.•A tree to store probability ranges of ngrams found in non malicious payloads.•OCPAD has high Detection Rate and low False Positives.•Theoretical and experimental comparison with other methods.

论文关键词:Anomaly detection,Payload analysis,Intrusion detection

论文评审过程:Received 27 October 2015, Revised 24 July 2016, Accepted 25 July 2016, Available online 2 August 2016, Version of Record 5 August 2016.

论文官网地址:https://doi.org/10.1016/j.eswa.2016.07.036