2020/12/21 by Tommaso Zoppi, Zoppi, Tommaso, Andrea Ceccarelli +5 · 2 citations
Computer Science · #Advanced Malware Detection Techniques #Anomaly Detection Techniques and Applications #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI)
paper · pdf · doi:10.48550/arxiv.2012.11354
openalex publication_date 2020/12/21 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Anomaly detection aims at identifying unexpected fluctuations in the expected\nbehavior of a given system. It is acknowledged as a reliable answer to the\nidentification of zero-day attacks to such extent, several ML algorithms that\nsuit for binary classification have been proposed throughout years. However,\nthe experimental comparison of a wide pool of unsupervised algorithms for\nanomaly-based intrusion detection against a comprehensive set of attacks\ndatasets was not investigated yet. To fill such gap, we exercise seventeen\nunsupervised anomaly detection algorithms on eleven attack datasets. Results\nallow elaborating on a wide range of arguments, from the behavior of the\nindividual algorithm to the suitability of the datasets to anomaly detection.\nWe conclude that algorithms as Isolation Forests, One-Class Support Vector\nMachines and Self-Organizing Maps are more effective than their counterparts\nfor intrusion detection, while clustering algorithms represent a good\nalternative due to their low computational complexity. Further, we detail how\nattacks with unstable, distributed or non-repeatable behavior as Fuzzing, Worms\nand Botnets are more difficult to detect. Ultimately, we digress on\ncapabilities of algorithms in detecting anomalies generated by a wide pool of\nunknown attacks, showing that achieved metric scores do not vary with respect\nto identifying single attacks.\n