Generally, intrusion behavior is regarded as a two-class problem in the research on intrusion detection, which includes normal and abnormal. It needs a training set of pure data which is labeled as normal and abnormal. But in practice, it is hard to find this data set, and traditional intrusion detection approaches can not detect some new intrusion behaviors which have not been labeled before. However, OCSVM-based intrusion detection approaches do not need any labeled data set, and attempt to find anomaly buried in the data.
Computer and Modernization