Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6750045
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T12:45:43+00:00 2026-05-26T12:45:43+00:00

Is there a machine learning concept (algorithm or multi-classifier system) that can detect the

  • 0

Is there a machine learning concept (algorithm or multi-classifier system) that can detect the variance of network attacks(or try to).

One of the biggest problems for signature based intrusion detection systems is the inability to detect new or variant attacks.

Reading up, anomaly detection seems to still be a statistical based en-devour it refers to detecting patterns in a given data set which isn’t the same as detecting variation in packet payloads. Anomaly based NIDS monitors network traffic and compares it against an established baseline of a normal traffic profile. The baseline characterizes what is “normal” for the network – such as the normal bandwidth usage, the common protocols used, correct combinations of ports numbers and devices etc

Say some one uses Virus A to propagate through a network then some one writes a rule to stop Virus A but another person writes a “variation” of Virus A called Virus B purely for the purposes of evading that initial rule but still using most if not all of the same tactics/code. Is there not a way to detect variance?

If there is whats the umbrella term it would come under, as ive been under the illusion that anomaly detection was it.

Could machine learning be used for pattern recognition(rather than pattern matching) at the packet payload level?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T12:45:43+00:00Added an answer on May 26, 2026 at 12:45 pm

    i think your intution to look at machine learning techniques is correct, or will turn out to be correct (One of the biggest problems for signature based intrusion detection systems is the inability to detect new or variant attacks.) The superior performance of ML techiques is in general due to the ability of these algorithms to generalize (a multiplicity of soft constraints rather than a few hard constraints). and to adapt (updates based on new training instances to frustrate simple countermeasures)–two attributes that i would imagine are crucial for identifying network attacks.

    The theoretical promise aside, there are practical difficulties with applying ML techniques to problems like the one recited in the OP. By far the most significant is the difficultly in gathering data to train the classifier. In particular, reliably labeling data points as “intrusion” is probably not easy; likewise, my guess is that these instances are sparsely distributed in the raw data.”

    I suppose it’s this limitation that has led to the increased interest (as evidenced at least by the published literature) in applying unsupervised ML techniques to problems like network intrusion detection.

    Unsupervised techniques differ from supervised techniques in that the data is fed to the algorithms without a response variable (i.e., without the class labels). In these cases you are relying on the algorithm to discern structure in the data–i.e., some inherent ordering in the data into reasonably stable groups or clusters (possibly what you the OP had in mind by “variance.” So with an unsupervised technique, there is no need to explicitly show the algorithm instances of each class, nor is it necessary to establish baseline measurements, etc.

    The most frequently used unsupervised ML technique applied to problems of this type is probably the Kohonen Map (also sometimes called self-organizing map or SOM.)

    i use Kohonen Maps frequently, but so far not for this purpose. There are however, numerous published reports of their successful application in your domain of interest, e.g.,

    Dynamic Intrusion Detection Using Self-Organizing Maps

    Multiple Self-Organizing Maps for Intrusion Detection

    I know MATLAB has at least one available implementation of Kohonen Map–the SOM Toolbox. The homepage for this Toolbox also contains a brief introduction to Kohonen Maps.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm implementing a new machine learning algorithm in Java that extracts a prototype datastructure
Is there any virtual machine to test Android? How can I debug the program
Is there a way to get a unique machine-specific system ID in a Flex
When I defragment my XP machine I notice that there is a block of
I'm messing around with machine learning, and I've written a K Means algorithm implementation
I'm interested in writing certain software that uses machine learning, and performs certain actions
I'm sketching a design of something (machine learning of functions) that will preferably want
I'm just learning Git and there is something I can't work out. After creating
Are there any machine learning libraries in C#? I'm after something like WEKA .
I am interested in learning as much as i can about tuning a multi-threaded

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.