Research Article

Application-Level Unsupervised Outlier-Based Intrusion Detection and Prevention

Excerpt 2

Features extracted from two sample invocations of process method.
1.0 1.225 0.5 0.5 0.333 0.333 0.0 Thread_1422880298849000568
0.5 1.853 0.5 1.0 0.143 0.143 0.0 Thread_8140491395022634864
On each line, features in this order: min path frequency, max
number variation, max string length variation, parameter’s
JSON length variation, min 3-gramfrequency, min 1-gram
frequency, exception(0/1), thread label