The Experts below are selected from a list of 11466 Experts worldwide ranked by ideXlab platform

Ryszard S. Michalski - One of the best experts on this subject based on the ideXlab platform.

  • Learning User Models for Computer Intrusion Detection: Preliminary Results from Natural Induction Approach
    2005
    Co-Authors: Ryszard S. Michalski, Kenneth A. Kaufman, Jaroslaw Pietrzykowski, Bartłomiej Śnieżyński, Janusz Wojtusiak
    Abstract:

    This research was supported in part by the UMCB/LUCITE #32 grant, and in part by the National Science Foundation under Grants No. IIS-0097476 and IIS-9906858.

  • Selecting Examples for Partial Memory Learning
    Machine Learning, 2000
    Co-Authors: Marcus A. Maloof, Ryszard S. Michalski
    Abstract:

    This paper describes a method for selecting training examples for a partial memory learning system. The method selects extreme examples that lie at the boundaries of concept descriptions and uses these examples with new training examples to induce new concept descriptions. Forgetting mechanisms also may be active to remove examples from partial memory that are irrelevant or outdated for the learning task. Using an implementation of the method, we conducted a lesion study and a direct comparison to examine the effects of partial memory learning on predictive accuracy and on the number of training examples maintained during learning. These experiments involved the STAGGER Concepts, a synthetic problem, and two real-world problems: a blasting cap detection problem and a Computer Intrusion detection problem. Experimental results suggest that the partial memory learner notably reduced memory requirements at the slight expense of predictive accuracy, and tracked concept drift as well as other learners designed for this task.

  • ICTAI - A method for partial-memory incremental learning and its application to Computer Intrusion detection
    Proceedings of 7th IEEE International Conference on Tools with Artificial Intelligence, 1
    Co-Authors: Marcus A. Maloof, Ryszard S. Michalski
    Abstract:

    This paper describes a partial-memory incremental learning method based on the AQ15c inductive learning system. The method maintains a representative set of past training examples that are used together with new examples to appropriately modify the currently held hypotheses. Incremental learning is evoked by feedback from the environment or from the user. Such a method is useful in applications involving intelligent agents acting in a changing environment, active vision, and dynamic knowledge-bases. For this study, the method is applied to the problem of Computer Intrusion detection in which symbolic profiles are learned for a Computer system's users. In the experiments, the proposed method yielded significant gains in terms of learning time and memory requirements at the expense of slightly lower predictive accuracy and higher concept complexity, when compared to batch learning, in which all examples are given at once.

Chaoyang He - One of the best experts on this subject based on the ideXlab platform.

  • IJCNN - Collecting Indicators of Compromise from Unstructured Text of Cybersecurity Articles using Neural-Based Sequence Labelling
    2019 International Joint Conference on Neural Networks (IJCNN), 2019
    Co-Authors: Zi Long, Shengping Zhou, Chaoyang He
    Abstract:

    Indicators of Compromise (IOCs) are artifacts observed on a network or in an operating system that can be utilized to indicate a Computer Intrusion and detect cyber-attacks in an early stage. Thus, they exert an important role in the field of cybersecurity. However, state-of-the-art IOCs detection systems rely heavily on hand-crafted features with expert knowledge of cybersecurity, and require large-scale manually annotated corpora to train an IOC classifier. In this paper, we propose using an end-to-end neural-based sequence labelling model to identify IOCs automatically from cybersecurity articles without expert knowledge of cybersecurity. By using a multi-head self-attention module and contextual features, we find that the proposed model is capable of gathering contextual information from texts of cybersecurity articles and performs better in the task of IOC identification. Experiments show that the proposed model outperforms other sequence labelling models, achieving the average F1-score of 89.0% on English cybersecurity article test set, and approximately the average F1-score of 81.8% on Chinese test set.

Zi Long - One of the best experts on this subject based on the ideXlab platform.

  • IJCNN - Collecting Indicators of Compromise from Unstructured Text of Cybersecurity Articles using Neural-Based Sequence Labelling
    2019 International Joint Conference on Neural Networks (IJCNN), 2019
    Co-Authors: Zi Long, Shengping Zhou, Chaoyang He
    Abstract:

    Indicators of Compromise (IOCs) are artifacts observed on a network or in an operating system that can be utilized to indicate a Computer Intrusion and detect cyber-attacks in an early stage. Thus, they exert an important role in the field of cybersecurity. However, state-of-the-art IOCs detection systems rely heavily on hand-crafted features with expert knowledge of cybersecurity, and require large-scale manually annotated corpora to train an IOC classifier. In this paper, we propose using an end-to-end neural-based sequence labelling model to identify IOCs automatically from cybersecurity articles without expert knowledge of cybersecurity. By using a multi-head self-attention module and contextual features, we find that the proposed model is capable of gathering contextual information from texts of cybersecurity articles and performs better in the task of IOC identification. Experiments show that the proposed model outperforms other sequence labelling models, achieving the average F1-score of 89.0% on English cybersecurity article test set, and approximately the average F1-score of 81.8% on Chinese test set.

  • Collecting Indicators of Compromise from Unstructured Text of Cybersecurity Articles using Neural-Based Sequence Labelling.
    arXiv: Computation and Language, 2019
    Co-Authors: Zi Long, Shengping Zhou
    Abstract:

    Indicators of Compromise (IOCs) are artifacts observed on a network or in an operating system that can be utilized to indicate a Computer Intrusion and detect cyber-attacks in an early stage. Thus, they exert an important role in the field of cybersecurity. However, state-of-the-art IOCs detection systems rely heavily on hand-crafted features with expert knowledge of cybersecurity, and require large-scale manually annotated corpora to train an IOC classifier. In this paper, we propose using an end-to-end neural-based sequence labelling model to identify IOCs automatically from cybersecurity articles without expert knowledge of cybersecurity. By using a multi-head self-attention module and contextual features, we find that the proposed model is capable of gathering contextual information from texts of cybersecurity articles and performs better in the task of IOC identification. Experiments show that the proposed model outperforms other sequence labelling models, achieving the average F1-score of 89.0% on English cybersecurity article test set, and approximately the average F1-score of 81.8% on Chinese test set.

Shengping Zhou - One of the best experts on this subject based on the ideXlab platform.

  • IJCNN - Collecting Indicators of Compromise from Unstructured Text of Cybersecurity Articles using Neural-Based Sequence Labelling
    2019 International Joint Conference on Neural Networks (IJCNN), 2019
    Co-Authors: Zi Long, Shengping Zhou, Chaoyang He
    Abstract:

    Indicators of Compromise (IOCs) are artifacts observed on a network or in an operating system that can be utilized to indicate a Computer Intrusion and detect cyber-attacks in an early stage. Thus, they exert an important role in the field of cybersecurity. However, state-of-the-art IOCs detection systems rely heavily on hand-crafted features with expert knowledge of cybersecurity, and require large-scale manually annotated corpora to train an IOC classifier. In this paper, we propose using an end-to-end neural-based sequence labelling model to identify IOCs automatically from cybersecurity articles without expert knowledge of cybersecurity. By using a multi-head self-attention module and contextual features, we find that the proposed model is capable of gathering contextual information from texts of cybersecurity articles and performs better in the task of IOC identification. Experiments show that the proposed model outperforms other sequence labelling models, achieving the average F1-score of 89.0% on English cybersecurity article test set, and approximately the average F1-score of 81.8% on Chinese test set.

  • Collecting Indicators of Compromise from Unstructured Text of Cybersecurity Articles using Neural-Based Sequence Labelling.
    arXiv: Computation and Language, 2019
    Co-Authors: Zi Long, Shengping Zhou
    Abstract:

    Indicators of Compromise (IOCs) are artifacts observed on a network or in an operating system that can be utilized to indicate a Computer Intrusion and detect cyber-attacks in an early stage. Thus, they exert an important role in the field of cybersecurity. However, state-of-the-art IOCs detection systems rely heavily on hand-crafted features with expert knowledge of cybersecurity, and require large-scale manually annotated corpora to train an IOC classifier. In this paper, we propose using an end-to-end neural-based sequence labelling model to identify IOCs automatically from cybersecurity articles without expert knowledge of cybersecurity. By using a multi-head self-attention module and contextual features, we find that the proposed model is capable of gathering contextual information from texts of cybersecurity articles and performs better in the task of IOC identification. Experiments show that the proposed model outperforms other sequence labelling models, achieving the average F1-score of 89.0% on English cybersecurity article test set, and approximately the average F1-score of 81.8% on Chinese test set.

Marcus A. Maloof - One of the best experts on this subject based on the ideXlab platform.

  • Selecting Examples for Partial Memory Learning
    Machine Learning, 2000
    Co-Authors: Marcus A. Maloof, Ryszard S. Michalski
    Abstract:

    This paper describes a method for selecting training examples for a partial memory learning system. The method selects extreme examples that lie at the boundaries of concept descriptions and uses these examples with new training examples to induce new concept descriptions. Forgetting mechanisms also may be active to remove examples from partial memory that are irrelevant or outdated for the learning task. Using an implementation of the method, we conducted a lesion study and a direct comparison to examine the effects of partial memory learning on predictive accuracy and on the number of training examples maintained during learning. These experiments involved the STAGGER Concepts, a synthetic problem, and two real-world problems: a blasting cap detection problem and a Computer Intrusion detection problem. Experimental results suggest that the partial memory learner notably reduced memory requirements at the slight expense of predictive accuracy, and tracked concept drift as well as other learners designed for this task.

  • ICTAI - A method for partial-memory incremental learning and its application to Computer Intrusion detection
    Proceedings of 7th IEEE International Conference on Tools with Artificial Intelligence, 1
    Co-Authors: Marcus A. Maloof, Ryszard S. Michalski
    Abstract:

    This paper describes a partial-memory incremental learning method based on the AQ15c inductive learning system. The method maintains a representative set of past training examples that are used together with new examples to appropriately modify the currently held hypotheses. Incremental learning is evoked by feedback from the environment or from the user. Such a method is useful in applications involving intelligent agents acting in a changing environment, active vision, and dynamic knowledge-bases. For this study, the method is applied to the problem of Computer Intrusion detection in which symbolic profiles are learned for a Computer system's users. In the experiments, the proposed method yielded significant gains in terms of learning time and memory requirements at the expense of slightly lower predictive accuracy and higher concept complexity, when compared to batch learning, in which all examples are given at once.