Preliminary Results on Masquerader Detection using Compression Based Similarity Metrics

Autores/as

  • Maximiliano Bertacchini Instituto de Investigaciones Cientícas y Técnicas de las Fuerzas Armadas, Argentina
  • Pablo I. Fierens Instituto Tecnológico de Buenos Aires, Argentina

Palabras clave:

Kolmogorov complexity, command behavior, masquerade detection, normalized compression distance, similarity metrics

Resumen

This paper extends a series of experiments performed by Schonlau et al. [1] on the detection of computer masqueraders (i.e. illegitimate users trying to impersonate legitimate ones). A compression-based classication algorithm called Normalized Compression Distance or NCD, developed by Vitányi et al. [2] is applied on the same data set. It is shown that the NCD-based approach performs as well as the methods previously tried by Schonlau et al. Future work, possible enhancements and directions of further research on this topic are presented as well.

Descargas

Publicado

2007-02-02

Cómo citar

Bertacchini, M., & Fierens, P. I. (2007). Preliminary Results on Masquerader Detection using Compression Based Similarity Metrics. SADIO Electronic Journal of Informatics and Operations Research, 7, 31-42. https://revistas.unlp.edu.ar/ejs/article/view/17534