You are on page 1of 6

Survey of Fraud Detection Techniques

Yufeng Kou, Chang-Tien Lu, Sirirat Sirwongwattana Yo-Ping Huang


Dept. of Computer Science Dept. of Computer Science
Virginia Polytechnic Institute and Engineering
and State University Tatung University
Falls Church, VA 22043, USA Taipei, Taiwan 10451
{ykou,ctlu,ssiriwon}@vt.edu yphuang@cse.ttu.edu.tw

Abstract this information to develop more sophisticated fraud tech-


niques. In addition, most of the attacked data are related to

In order to reduce the huge nancial loss caused by var- business secret and user privacy, which are impossible for

ious frauds, a number of modern techniques have been de- public analysis. To some degree, the limited information ex-

veloped for fraud detection. Fraud detection involves mon- change constrains the development of new fraud detection

itoring the behavior of populations of users in order to es- technologies. The fraud cases have to be detected from the

timate, detect, or avoid undesirable behavior. Undesirable available huge data sets such as the logged data and user be-

behavior is a broad term including delinquency, fraud, in- havior. At present, fraud detection has been implemented by

trusion, and account defaulting. This paper presents a com- a number of methods such as data mining, statistics, and ar-

prehensive survey about the techniques for identifying dif- ticial intelligence. Fraud is discovered from anomalies in

ferent types of frauds, including credit card fraud, telecom- data and patterns. The types of frauds in this paper include

munication fraud, and computer intrusion. The goal of this credit card frauds, telecommunication frauds, and computer

paper is to provide a comprehensive review of different tech- intrusion.

niques to detect frauds. Credit Card Fraud. Credit card fraud is divided into
two types: ofine fraud and online fraud. Ofine fraud is
committed by using a stolen physical card at storefront or
call center. In most cases, the institution issuing the card
Keywords: Fraud detection, computer intrusion, data can lock it before it is used in a fraudulent manner. Online

mining, knowledge discovery, neural network. fraud is committed via web, phone shopping or cardholder-
not-present. The criminals only need the card information
(Id, expiration date, etc.), not necessary to have the card in
1. Introduction
hand or simulate the cardholder's signature.

The Association of Certied Fraud Examiners (ACFE) Computer Intrusion. Intrusion is dened as the poten-
dened fraud as “the use of one's occupation for personal tial possibility of a deliberate unauthorized attempt to ac-
enrichment through the deliberate misuse or application of cess information, manipulate information, or render a sys-
the employing organization's resources or assets [1].” In the tem unreliable or unusable. Intruders may be from an out-
technological systems, fraudulent activities have occurred sider (or hacker) and an insider who knows the layout of the
in many areas of daily life such as telecommunication net- system, where the valuable data is and what security pre-
works, mobile communications, on-line banking, and E- cautions are in place. Computer intrusion can be classied
commerce. These frauds lead to substantial nancial loss into two categories: misuse intrusions and anomaly intru-
for individuals, government, and business. Consequentially, sions. Misuse intrusions are well-dened attacks on known
fraud detection has become an important issue to be ex- weak points of a system. Anomaly intrusions are based on
plored. observations of deviations from normal system usage pat-

“Fraud detection involves identifying fraud as quickly as terns. These include attempted break-ins, masquerade at-

possible once it has been perpetrated. [6]” Fraud detection tacks, leakage, denial of service, and malicious use [4].

methods are continuously developed to defend criminals in Telecommunication Fraud. Fraud is costly to a network
adapting to their strategies. Fraud methods and fraud detec- carrier both in terms of lost income and wasted capacity.
tion can not be discussed in public since criminals may use The various types of telecommunication fraud can be clas-
sied into two categories: subscription fraud and superim- databases. They can only be used for identifying frauds with
posed fraud. Subscription fraud denotes the behavior of us- known patterns. An advantage of using unsupervised meth-
ing false identity to subscribe a service and evade payment. ods over supervised methods is that previously undiscov-
Cases of bad debt are also included in this category. “Su- ered types of fraud may be detected. Bolton and Hand pro-
perimposed fraud is the use of a service without having the posed unsupervised credit card fraud detection, using be-
necessary authority and is usually detected by the appear- havioral outlier detection techniques [5]. Abnormal spend-
ance of 'phantom' call on a bill. [6]” Superimposed fraud ing behavior and frequency of transactions will be identied
includes mobile phone cloning, ghosting (making free calls as outliers, which are possible fraud cases.
by deceiving the billing systems), insider fraud, and tum- Neural Networks. A neural network is a set of inter-
bling (randomly or serially changing the serial number of a connected nodes designed to imitate the functioning of the
cell phone). human brain [16]. Each node has a weighted connec-
In general, the objective of fraud detection is to maxi- tion to several other nodes in adjacent layers. Individual
mize correct predictions and maintain incorrect predictions nodes take the input received from connected nodes and
at an acceptable level [30]. A high correct diagnostic prob- use the weights together with a simple function to com-
ability can be implied by minimizing probability of unde- pute output values. Neural networks come in many shapes
tected fraud and false alarms. Some technical terms are de- and forms and can be constructed for supervised or unsu-
scribed as follows. False alarm rate (or false positive rate) pervised learning. The user species the number of hidden
is the percentage of legitimate transactions that are incor- layers as well as the number of nodes within a specic hid-
rectly identied as fraudulent. Fraud catching rate (or true den layer. Depending on the application, the output layer of
positive rate or detection accuracy rate) is the percentage of the neural network may contain one or several nodes.
fraudulent transactions that are correctly identied as fraud-
CARDWATCH [2] features neural networks trained
ulent. False Negative rate is the percentage of fraudulent
with the past data of a particular customer. It makes the net-
transactions that are incorrectly identied as legitimate. In
work process the current spending patterns to detect pos-
a fraud detection system, it is important to dene perfor-
sible anomalies. Brause and Langsdorf proposed the rule-
mance metrics carefully. Several fraud detection techniques
based association system combined with the neuro-adaptive
use metrics like the detection rate, false alarm rate, and av-
approach [7]. Falcon developed by HNC uses feed-forward
erage time of detection. The typical fraud detection tech-
Articial Neural Networks trained on a variant of a back-
niques attempt to maximize accuracy rate and minimize
propagation training algorithm [17]. Machine learning,
false alarm rate.
adaptive Pattern Recognition, neural networks, and statis-
tical modeling are employed to develop Falcon predictive

2. Credit Card Fraud Detection models to provide a measure of certainty about whether a
particular transaction is fraudulent. A neural MLP-based

Credit card fraud detection is quite condential and is not classier is another example using neural networks [12]. It

much disclosed in public. Some available techniques tech- acts only on the information of the operation itself and of its

niques are discussed as follows. immediate previous history, but not on historic databases of

Outlier Detection. An outlier is an observation that de- past cardholder activities. A parallel Granular Neural Net-

viates so much from other observations as to arouse suspi- work (GNN) method uses fuzzy neural network and rule-

cion that it was generated by a different mechanism [20]. based approach [35]. The neural system is trained in par-

Unsupervised learning approach is employed to this model. allel using training data sets, and then the trained parallel

Usually, the result of unsupervised learning is a new expla- fuzzy neural network discovers fuzzy rules for future pre-

nation or representation of the observation data, which will diction. CyberSource introduces a hybrid model, combin-

then lead to improved future responses or decisions. Unsu- ing an expert system with a neural network to increase its

pervised methods do not need the prior knowledge of fraud- statistic modeling and reduce the number of “false” rejec-

ulent and non-fraudulent transactions in historical database, tions [10].

but instead detect changes in behavior or unusual transac- Research Issues. It is an interesting issue to incorpo-
tions. These methods are based on the data statistics. They rate spatial information to the detection system. For exam-
build a distribution model for the given data set and iden- ple, if the orders like big furniture or cars are purchased to
tify the observations deviating signicantly from this distri- ship to the address that is far away from the billing address,
bution as outliers, or potential fraud events. In supervised this transaction may be considered fraud. In meta-learning
methods, models are trained to discriminate between fraud- techniques for credit card fraud detection, a meta-classier
ulent and non-fraudulent behavior so that new observations is trained on the correlation of the predictions of the base
can be assigned to classes. Supervised methods require ac- classier [33]. It would be meaningful to dene effective
curate identication of fraudulent transactions in historical selection metrics for deciding best base classiers used for
meta-learning. Currently, for simplicity reasons, all the base Expert Systems. An expert system is dened as a com-
learners for credit card fraud detection use the same desired puting system capable of representing and reasoning about
distribution. It would be interesting to implement and eval- some knowledge-rich domain with a view to solving prob-
uate the credit card fraud detection system by using very lems and giving advice [25, 31]. Expert system detectors
large databases with skewed class distributions and non- encode knowledge about attacks as if-then rules. NIDES
uniform cost per error. developed by SRI uses the expert system approach to im-
plement intrusion detection system that performs real-time
monitoring of user activity [3]. NIDES consists of statis-
3. Computer Intrusion Detection
tical analysis component for anomaly detection and rule-
based analysis component for misuse detection.
Many intrusion detection systems base their operations
Neural Networks. NNID (Neural Network Intrusion
on analysis of audit data generated by the operating sys-
Detector) is an anomaly intrusion detection system imple-
tem. An audit trail is a record of activities on a system that
mented by a backpropagation neural network under UNIX
are logged to a le in chronologically sorted order. An in-
environment [29]. It is trained to identify users based on
trusion detection system is needed to automate and perform
what commands and how often they used during a day. It
system monitoring by keeping aggregate audit trail statis-
is easy to train and inexpensive because it operates off-line
tics. Intrusion detection approaches can be broadly classi-
on daily log data. ANN (Articial Neural Networks) pro-
ed into two categories based on model of intrusions: mis-
vides the ability to generalize from previously observed be-
use and anomaly detection.
havior (normal or malicious) to recognize similar future un-
Misuese detection attempts to recognize the attacks of
seen behavior for both anomaly detection and misuse de-
previously observed intrusions in the form of a pattern or
tection [15]. It is implemented by a backpropagation neu-
a signature (for example, frequent changes of directory or
ral network.
attempts to read a password le) and directly monitor for
the occurrence of these patterns [3, 14, 15, 21–23]. Misuse Model-based Reasoning. Model-based detection is a

approaches include expert systems, model-based reasoning, misuse detection technique that detects attacks through ob-

state transition analysis, and keystroke dynamics monitor- servable activities that infer an attack signature. There is a

ing [32]. Since specic attack sequences are encoded into database of attack scenarios containing a sequence of be-

misuse detection system, known attacks can be detected haviors making up the attack. Garvey and Lunt combined

very reliably with a low false alarm rate. Misuse detection is models of misuse with evidential reasoning [14]. The sys-

simpler than anomaly detection. However, a primary draw- tem accumulates more and more evidence for an intrusion

back of misuse detection is that it is not possible to antic- attempt until a threshold is crossed; at this point, it signals

ipate all the different attacks because it looks only known an intrusion attempt. A pattern matching approach based on

patterns of abuse. Colored Petri Nets to detect misuse intrusion is proposed by

Anomaly detection tries to establish a historical normal Kumar and Spafford [23]. It uses audit trails as input un-

prole for each user, and then use sufciently large devi- der UNIX environment.

ation from the prole to indicate possible intrusions [15, Data Mining. Data mining approaches can be applied
24, 29]. Anomaly detection approaches include statistical for intrusion detection. An important advantage of data min-
approaches, predictive pattern generation, and neural net- ing approach is that it can develop a new class of models to
works. The advantage of anomaly detection is that it is detect new attacks before they have been seen by human ex-
possible to detect novel attacks against systems, because perts. Classication model with association rules algorithm
it compares current activities against statistical models for and frequent episodes is developed for anomaly intrusion
past behavior, not tied with specic or pre-dened patterns. detection [24]. This approach can automatically generate
However, there are some of the weaknesses of this ap- concise and accurate detection models from large amount
proach. It is likely to have high rates of false alarm. Unusual of audit data. However, it requires a large amount of au-
but legitimate use may sometimes be considered anoma- dit data in order to compute the prole rule sets. More-
lous. Statistical measures of user prole can be gradually over, this learning process is an integral and continuous part
trained, so intruders can train such systems over a period of of an intrusion detection system because the rule sets used
time until intrusive behavior is considered normal. Also, it by the detection module may not be static over a long pe-
is not able to identify the specic type of attack that is oc- riod of time. A team of researchers at Columbia University
curring. Moreover, the anomaly detection systems are com- proposed the detection models using cost-sensitive machine
putationally expensive because of the overhead of keeping learning algorithms [34]. Audit data is analyzed by associ-
track of and updating several system prole metrics. ation rules algorithm in order to determine static features of

The techniques used in misuse detection and anomaly attack data.

detection are described as follows: State Transition Analysis. State Transition Analysis is
a misuse detection technique, which attacks are represented ing explicit information, where fraud criteria can be referred
as a sequence of state transitions of the monitored system. as rules. Rule-discovery methodology combining two data
Actions that contribute to intrusion scenarios are dened as levels, which are the customer data and behavior data (usage
transitions between states. Intrusion scenarios are dened in characteristics in a short time frame), is proposed in [28]. A
the form of state transition diagrams. Nodes represent sys- rule-set is selected by using a greedy algorithm with the ad-
tem states and arcs represent relevant actions. If a compro- justed thresholds. PDAT is a rule-based tool for intrusion
mised (nal) state is ever reached, an intrusion is said to detection developed by Siemens ZFE. Due to its exibility
have occurred. STAT(State Transition Analysis Tool) is a and broad applicability, PDAT is used for mobile fraud de-
rule-based expert system designed to seek out known pen- tection.
etrations in the audit trails of multi-user computer systems Rule-based analysis can be very difcult to manage be-
[22]. USTAT (UNIX State Transition Analysis Tool) is a cause the proper conguration of such rules requires pre-
UNIX-specic prototype of STAT [21]. cise, laborious, and time-consuming programming for each
Other Techniques. A genetic algorithm [8] is applied imaginable fraud possibility. The dynamic appearance of
to detect malicious intrusions and separate them from nor- multiple new fraud types demands that these rules be con-
mal use. A genetic algorithm is a method of articial intel- stantly adapted to include existing, emerging, and future
ligence problem solving based on the theory of Darwinian fraud options. Moreover, it also presents a major obstacle
evolution applied to mathematical models. This genetic al- to scalability. The more data the system must process, the
gorithm was designed so that each individual represented a more drastic is the performance downfall.
possible behavioral model. This approach provides a high Neural Networks. In recent years, neural networks have
detection rate and a low false alarm rate. Dokas and Ertoz played an important role in fraud detection. Neural Net-
proposed building rare class predictive models for identi- works can actually calculate user proles in an indepen-
fying known intrusions [11]. This method can address the dent manner, thus adapting more elegantly to the behav-
inability of standard data mining techniques when dealing ior of the various users. Neural Networks are claimed to
with skewed class distribution. substantially reduce operation costs. A project of the Euro-
Research Issues. Due to the incredibly large sizes of au- pean Commission, ASPeCT, investigated the feasibility of
dit data, audit trail reduction is signicant to retrieve in- the implementations with a rule-based approach and neu-
formation rapidly and efciently. Relationship between the ral networks approach, both supervised and unsupervised
types, amount of omission and the accuracy of detection learning based on data in toll tickets [26]. Three approaches
needs to be explored in depth. An attacker may perform sev- were presented in [36] based on toll tickets (call records
eral actions under different user identities. Non-parametric stored for billing purposes). First, a feed-forward neural net-
pattern recognition is useful when the statistical distribu- work based on supervised learning is used to learn a non-
tion of the underlying data is not available. The performance linear discriminative function to classify subscribers using
of intrusion detection system could be able to adapt to the summary statistics. Second, density estimation with Gaus-
increasement of the number of users. It would be interest- sian mixture model is applied to modeling the past behav-
ing to analyze the performance impact by optimizing the set ior of each subscriber and detecting any abnormalities from
of commands and the size of the value intervals when net- the past behavior. Third, Bayesian networks are used to de-
work is used by large amount of users. To reduce the false ne probabilistic models given the subscribers' behavior.
alarm rate, statistical analysis approach should be developed
Visualization Methods. Visualization techniques rely
to distinguish important and less important alarms.
on human pattern recognition to detect anomalies and are
provided with close-to-real-time data feeds. The idea is that

4. Telecommunication Fraud Detection while machine-based detection methods are largely static,
the human visual system is dynamic and can easily adapt
Previous work in the telecommunication fraud detection to the ever-changing techniques used by the fraudsters. Vi-
has concentrated mainly on identifying superimposed fraud. sual data mining is developed to combine human detection
Most techniques use Call Detail Record data to create be- with machine recognition. It usually provides a graphical
havior proles for the customer, and detect deviations from user interface to visualize the call information of differ-
these proles. These approaches are discussed as follows. ent subscribers across large geographical locations. Visual

Rule-based Approach.: A combination of absolute and data mining has been applied to detect international call-

differential usage is veried against certain rules in the rule- ing fraud [9].

based approach mapped to data in toll tickets [26]. With dif- Other Techniques. A call-based on-line fraud detec-
ferential analysis, exible criteria can be developed to de- tion system based on a hierarchical regime-switching model
tect any usage change in a detailed user behavior history. is implemented by using subscriber data from real mobile
Rule-based approach works best with user proles contain- communication network [19]. The model is trained by using
the EM algorithm in an incomplete data setting [18]. After dependence on system vendors. Thirdly, they require very
EM learning, the gradient-based discriminative training is accurate denitions of thresholds and parameters.
used to improve the performance. Location awareness of the There are other interesting areas of fraud detection, not
mobile phone can be used to detect cellular clones within a mentioned in this paper, such as voting irregularities, crim-
local system and to detect roamer clones [27]. Clones, by inal activities in e-commerce, insurance claims fraud, war-
denition, will exist at a different location from the legit- ranty fraud and abuse, and health card fraud.
imate mobile phone. Clone detection within user's current
system can be recognized by “too many locations” and “im-
References
possible locations”.
Research Issues. The problem of uncollectible debt in [1] Investigating Fraudulent Acts, UNIVERSITY OF HOUS-
telecommunication services is addressed by using a goal- TON SYSTEM ADMINISTRATIVE MEMORANDUM.

directed Bayesian network for classication, which distin- http://www.uhsa.uh.edu/sam/AM/01C04.htm, 2000.

guishes customers who are likely to have bad debt [13]. [2] E. Aleskerov, B. Freisleben, and B. Rao. Cardwatch: a neural

Since unsupervised learning does not require a priori knowl- network based database mining system for credit card fraud
detection. In Proceedings of Computational Intelligence for
edge of fraudulent data, it may be used to lter out much
Financial Engineering, pages 173–200, 1997.
normal behavior so that the successive supervised learning
[3] D. Anderson, T. Frivold, A. Tamaru, and A. Valdes. Next-
processing load is reduced for rule-based system and neu-
generation intrusion detection expert system (nides), soft-
ral network-based system. Exhaustive rule generation is an
ware users manual, beta-update release. Technical Report
interesting issue for rule based approach. The advantage is
SRI–CSL–95–07, Computer Science Laboratory, SRI Inter-
that the rule-generation step will not lose any of the possi-
national, 333 Ravenswood Avenue, Menlo Park, CA 94025-
ble candidates for good rules, and will not require compli- 3493, May 1994.
cated mechanisms. At present, the rule selection methodol-
[4] S. Axelsson. Research in intrusion-detection systems: A
ogy is implemented by a greedy algorithm, which requires survey. Technical Report 98–17, Department of Computer
the predened threshold. It would be interesting to imple- Engineering, Chalmers University of Technology, Goteborg,
ment non-greedy rule-selection procedures, which can cre- Sweden, dec 1998.
ate a more robust selection process. [5] R. J. Bolton and D. J. Hand. Unsupervised proling meth-
ods for fraud detection. In conference of Credit Scoring and
Credit Control VII, Edinburgh, UK, Sept 5-7, 2001.
5. Conclusions
[6] R. J. Bolton and D. J. Hand. Statistical fraud detection: A
review. In Statistical Science, volume 17, pages 235–255,
In this paper, fraud detection in three areas, credit card 2002.
fraud detection, computer intrusion detection, and telecom-
[7] R. Brause, T. Langsdorf, and M. Hepp. Credit card fraud de-
munication is discussed. It presents the characteristics of tection by adaptive neural data mining. In Proceedings of
fraud types, the need of fraud detection systems, several cur- the 11th IEEE International Conference on Tools with Arti-
rent fraud detection techniques, and the possibility of future cial Intelligence, pages 103–106, 1999.
works. [8] A. Chittur. Model generation for an intrusion detection sys-
Due to the security issues, only a few approaches for tem using genetic algorithms. In Ossining High school Hon-

credit card detection are available in public. Among them, ors Thesis, 2001.

neural networks approach is a very popular tool. However, [9] K. C. Cox, S. G. Eick, G. J. Wills, and R. J. Brachman. Visual

it is difcult to implement because of lack of available data data mining: Recognizing telephone calling fraud. J. Data
Mining and Knowledge Discovery, 1(2):225–231, 1997.
set. For intrusion detection, some techniques have been ap-
[10] CyberSource company. Credit card fraud management.
plied to the real application. However, it is difcult to test
http://www.cybersource.com, 1996.
existing intrusion detection systems, simulate potential at-
[11] P. Dokas, L. Ertoz, V. Kumar, A. Lazarevic, J. Srivastava, and
tack scenarios, and duplicate known attacks. Moreover, in-
P.-N. Tan. Data mining for network intrusion detection. In
trusion detection system has poor portability because the
Proc. NSF Workshop on Next Generation Data Mining, Bal-
system and its rule set must be specic to the environment
timore, MD, November, 2002.
being monitored. Most telecommunication fraud detection
[12] J. R. Dorronsoro, F. Ginel, C. Sanchez, and C. S. Cruz.
techniques explore data set of toll tickets and detect fraud
Neural fraud detection in credit card operations. In IEEE
from call patterns. These systems are effective against sev-
Transactions on Neural Networks, volume 8, pages 827–834,
eral kinds of frauds, but still have some main problems: 1997.
Firstly, they cannot support fraud incidences that not fol- [13] K. J. Ezawa and S. W. Norton. Constructing bayesian net-
low the proles. Secondly, these systems require upgrading works to predict uncollectible telecommunications accounts.
to keep them up to date with current frauds methods. Up- Ieee Expert-Intelligent Systems & Their Applications, 11:45–
grade and maintenance costs are high and mean continual 51, 1996.
[14] T. D. Garvey and T. F. Lunt. Model based intrusion detec- Intrusion Detection Expert System (IDES) – Final Technical
tion. In Proceedings of the 14th National Computer Security Report. Technical report, SRI Computer Science Laboratory,
Conference,October 1991. SRI International, Menlo Park, CA, Feb. 1992.

[15] A. K. Ghosh and A. Schwartzbard. A study in using neural [26] Y. Moreau, B. Preneel, P. Burge, J. Shawe-Taylor, C. Stoer-
networks for anomaly and misuse detection. In Proceedings mann, and C. Cooke. Novel techniques for fraud detection in
of the 8th USENIX Security Symposium, D.C., 1999. mobile telecommunication networks. In ACTS Mobile Sum-

[16] S. Ghosh and D. L. Reilly. Credit card fraud detection with a mit, Grenada, Spain, 1997.

neural-network. In J. F. Nunamaker and R. H. Sprague, ed- [27] S. Patel. Location identity and wireless fraud detection. In

itors, Proceedings of the 27th Annual Hawaii International ICPWC'97 Technical Program, Lucent technologies, Wire-

Conference on System Science. Volume 3 : Information Sys- less Secure Communications Lab, 1997.

tems: DSS/Knowledge-Based Systems, pages 621–630, Los [28] S. Rosset, U. Murad, E. Neumann, Y. Idan, and G. Pinkas.
Alamitos, CA, USA, Jan. 1994. IEEE Computer Society Discovery of fraud rules for telecommunicationschallenges
Press. and solutions. In Proceedings of the fth ACM SIGKDD

[17] K. Hassibi. Detecting payment card fraud with neural net- international conference on Knowledge discovery and data
works. In Business application of Neural Networks, P.J.G. mining, pages 409–413. ACM Press, 1999.
Lisboa, A.Vellido, B.Edisbury Eds. Singopore: World Scien- [29] J. Ryan, M.-J. Lin, and R. Miikkulainen. Intrusion detec-
tic, 2000. tion with neural networks. In M. I. Jordan, M. J. Kearns, and

[18] Hollmn and Jaakko. Probabilistic Approaches to Fraud De- S. A. Solla, editors, Advances in Neural Information Pro-

tection, Licentiate's Thesis. Helsinki University of Tech- cessing Systems, volume 10. The MIT Press, 1998.

nology, Department of Computer Science and Engineering, [30] SAS Institute. Using Data Mining Techniques for Fraud De-
1999. tection: A Best Practices Approach to Government Technol-

[19] J. Hollmn and V. Tresp. Call-based fraud detection in mo- ogy Solutions, Whitepapers. http://www.sas.com, 1996.

bile communication networks using a hierarchical regime- [31] M. Sebring, E. Shellhouse, M. Hanna, and R. Whitehurst.
switching model. In Proceedings of the 1998 conference on Expert system in intrusion detection: A case study. In Pro-
Advances in neural information processing systems II, pages ceedings of the 11th National Computer Security Confer-
889–895. MIT Press, 1999. ence, pages 85–91, October 1988.

[20] E. Hung and D. W. Cheung. Parallel Algo- [32] S. E. Smaha and J. Winslow. Misuse detection tools. In Com-

rithm for Mining Outliers in Large Database. puter Security Journal 10(1), pages 39 – 49, Spring 1994.

http://citeseer.nj.nec.com/hung99parallel.html, 1999. [33] S. Stolfo, W. Fan, W. Lee, A. Prodromidis, and P. Chan.

[21] K. Ilgun. USTAT: A real-time intrusion detection system for Credit card fraud detection using meta-learning: Issues and

UNIX. In Proceedings of the 1993 IEEE Symposium on Re- initial results, 1997.

search in Security and Privacy, pages 16–28, Oakland, CA, [34] S. J. Stolfo, W. Lee, P. K. Chan, W. Fan, and E. Eskin.
1993. Data mining-based intrusion detectors: An overview of the

[22] K. Ilgun, R. A. Kemmerer, and P. A. Porras. State transition columbia ids project. In ACM Transactions on Information

analysis: A rule-based intrusion detection approach. Soft- and System Security, TISSEC, volume 3, pages 5–14, 2001.

ware Engineering, 21(3):181–199, 1995. [35] M. Syeda, Y.-Q. Zhang, and Y. Pan. Parallel granular neural

[23] S. Kumar and E. H. Spafford. A Pattern Matching Model for networks for fast credit card fraud detection. In Proceedings

Misuse Intrusion Detection. In Proceedings of the 17th Na- of the 2002 IEEE International Conference, volume 1, pages

tional Computer Security Conference, pages 11–21, 1994. 572–577, 2002.

[36] M. Taniguchi, M. Haft, J. Hollmen, and V. Tresp. Fraud de-


[24] W. Lee and S. Stolfo. Data mining approaches for intrusion
tection in communication networks using neural and proba-
detection. In Proceedings of the 7th USENIX Security Sym-
bilistic methods. In Proceedings of the 1998 IEEE Interna-
posium, San Antonio, TX, 1998.
tional Conference in Acoustics, Speech and Signal Process-
[25] T. F. Lunt, A. Tamaru, F. Gilham, R. Jagannathan, P. G. Neu-
ing, volume 2, pages 1241–1244, 1998.
mann, H. S. Javitz, A. Valdes, and T. D. Garvey. A Real-Time

You might also like