62 ◾ Data Mining and Machine Learning in Cybersecurity
3.3.1.1 Classification Using Association Rules
Agrawal et al. (1993) introduced association rules to capture and represent causal
relationships among attributes in a multidimensional database. Association rules
classication describes the frequent patterns in a data set, e.g., computer and anti-
virus software that appear frequently together in a transaction data set.
For example, let us assume that an association rule from the shell command
history le of a user, which is a stream of commands and their arguments, is
trn rec.humor, [0.3, 0.1]. is association rule indicates that 30% of the time
when the user invokes trn, he or she is reading the news in rec.humor, and reading
this new