Abstract
dc:description.abstract<p>Insider threat detection is still a relatively new area of study in Computer Science. Perhaps the most thoroughly researched topic is in the area of masquerade detection. A masquerader is someone posing as a specific legitimate user when they are really another person. Several different ways of determining the presence of a masquerader have been proposed and researched, but there are significant problems including low detection rates and high false positive results. Roy Maxion and Kevin Killourhy utilized a Naive Bayes classifier for detection using enriched Unix command lines, which are command line entries that still contain flags and other data. They discovered a problem with users that they dubbed supermasqueraders. These were users that would avoid detection no matter what data sets they were tested against. This was due to an intrinsic problem in the Naive Bayes classifier which would miss positive classifications when more than a small portion of the test block command lines were never before seen commands. They added a simple secondary check to solve this problem which greatly improved the results obtained. This thesis will attempt to validate and improve upon results obtained by Maxion and Killourhy in their paper, 'Naive Bayes as a Masquerade Detector: Addressing a Chronic Failure.</p>
Degree
thesis:*- Name thesis:degree_name
- Master of Science (MS) in Computer Science
- Level thesis:degree_level
- Thesis: EWU Only
- Discipline thesis:degree_discipline
- Computer Science
- Year
- 2010
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Salsbury, Eric
Subjects
dc:subject × 2Rights
dc:rights- Statement dc:rights
-
- Access perpetually restricted to EWU users with an active EWU NetID
Identifiers
dc:identifier.*- Repository record dc:identifier
- https://dc.ewu.edu/theses/803
- OAI identifier oai:identifier
- oai:dc.ewu.edu:theses-1801