{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/95622"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/95622","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Effective detection of security compromises in enterprises using feature engineering","abstract":"The student, Jiayi Duan, submitted this Thesis for approval on 2016-12-07 at 23:45.","abstract_html":"The student, Jiayi Duan, submitted this Thesis for approval on 2016-12-07 at 23:45.","abstract_has_math":false,"creators":["Duan, Jiayi"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Vasudevan, Shobha"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2017,"date_issued":"2017-03-01T17:02:07Z","date_published":"2017-03-01T17:02:07Z","updated_at":"2026-07-22T22:26:37Z","subjects":["Feature engineering"],"languages":["en"],"rights":["Copyright 2016 Jiayi Duan"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/95622","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Vasudevan, Shobha"]},{"key":"dc:creator","label":"Author","values":["Duan, Jiayi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2017-03-01T17:02:07Z","2019-03-02T10:15:30Z","2016-12-08","2016-12"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Feature engineering"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2016 Jiayi Duan"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/95622"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The student, Jiayi Duan, submitted this Thesis for approval on 2016-12-07 at 23:45.","This Thesis was approved for publication on 2016-12-08 at 09:38.","DSpace SAF Submission Ingestion Package generated from Vireo submission #10478 on 2017-02-28 at 14:43:24","Made available in DSpace on 2017-03-01T17:02:07Z (GMT). No. of bitstreams: 2 DUAN-THESIS-2016.pdf: 1112146 bytes, checksum: d77746635b466f3808926f8232c490a0 (MD5) LICENSE.txt: 4207 bytes, checksum: 18ee6948ab9e275c21515c3e9282f4d5 (MD5) Previous issue date: 2016-12-08","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:02:22Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:03:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:05:02Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","\"We present a method to effectively detect malicious activity in the data of enterprise logs. Our method involves feature engineering, or generating new features by applying operators on the features of the raw data. We apply the Fourier expansion of Boolean functions to generate parity functions on feature subsets, or parity features. We also investigate a heuristic method of applying Boolean operators to raw data features, generating propositional features. We demonstrate with real data sets that the engineered features enhance the performance of classifiers and clustering algorithms. As compared to classification of raw data features, the engineered features achieve up to 50.6% improvement in malicious recall while sacrificing no more than 0.47% in accuracy. Clustering with respect to the engineered features finds up to 6 \"\"pure\"\" malicious clusters, as compared to 0 \"\"pure\"\" clusters with raw data features. In one case, exactly one (1) engineered feature could achieve higher performance than 91 raw data features. In general, a small number (<10) of engineered features achieve higher performance than raw data features.\"","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2018-12-01","The student, Jiayi Duan, accepted the attached license on 2016-12-07 at 23:36.","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:06:55Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 98738 on 2019-03-02T10:15:30Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Effective detection of security compromises in enterprises using feature engineering"]}]}],"canonical_facts":{"dc:contributor":["Vasudevan, Shobha"],"dc:creator":["Duan, Jiayi"],"dc:date":["2017-03-01T17:02:07Z","2019-03-02T10:15:30Z","2016-12-08","2016-12"],"dc:description":["The student, Jiayi Duan, submitted this Thesis for approval on 2016-12-07 at 23:45.","This Thesis was approved for publication on 2016-12-08 at 09:38.","DSpace SAF Submission Ingestion Package generated from Vireo submission #10478 on 2017-02-28 at 14:43:24","Made available in DSpace on 2017-03-01T17:02:07Z (GMT). No. of bitstreams: 2 DUAN-THESIS-2016.pdf: 1112146 bytes, checksum: d77746635b466f3808926f8232c490a0 (MD5) LICENSE.txt: 4207 bytes, checksum: 18ee6948ab9e275c21515c3e9282f4d5 (MD5) Previous issue date: 2016-12-08","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:02:22Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:03:32Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:05:02Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","\"We present a method to effectively detect malicious activity in the data of enterprise logs. Our method involves feature engineering, or generating new features by applying operators on the features of the raw data. We apply the Fourier expansion of Boolean functions to generate parity functions on feature subsets, or parity features. We also investigate a heuristic method of applying Boolean operators to raw data features, generating propositional features. We demonstrate with real data sets that the engineered features enhance the performance of classifiers and clustering algorithms. As compared to classification of raw data features, the engineered features achieve up to 50.6% improvement in malicious recall while sacrificing no more than 0.47% in accuracy. Clustering with respect to the engineered features finds up to 6 \"\"pure\"\" malicious clusters, as compared to 0 \"\"pure\"\" clusters with raw data features. In one case, exactly one (1) engineered feature could achieve higher performance than 91 raw data features. In general, a small number (<10) of engineered features achieve higher performance than raw data features.\"","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2018-12-01","The student, Jiayi Duan, accepted the attached license on 2016-12-07 at 23:36.","Embargo set by: Seth Robbins for item 98738 Lift date: 2019-03-01T17:06:55Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 98738 on 2019-03-02T10:15:30Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/95622"],"dc:language":["en"],"dc:rights":["Copyright 2016 Jiayi Duan"],"dc:subject":["Feature engineering"],"dc:title":["Effective detection of security compromises in enterprises using feature engineering"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:26:37Z"}