• DocumentCode
    1719033
  • Title

    Needles in Haystacks: Practical Intrusion Detection from Theoretical Results

  • Author

    Marin, Gerald A. ; Allen, William H.

  • Author_Institution
    Florida Inst. of Technol.
  • fYear
    2006
  • Firstpage
    571
  • Lastpage
    573
  • Abstract
    Many researchers are working towards discovering techniques that can alert network administrators to the presence of previously unseen attacks in their networks. Here we focus on attacks, such as denial-of service attacks, that depend on multiple packets being sent over minutes or, at least, several seconds. No definitive technique has been demonstrated that can guarantee a substantial probability of detection while keeping probability of false alarm at an acceptable level. However, theoretical work by Li, Jia, and Zhao (referenced below) describes an interesting approach based on observing changes to autocorrelations obtained over time from measured traffic. Their work provides a theoretical way of estimating probability of detection vs. probability of false alarm. They make assumptions concerning availability of a background template and normality of residuals that bear examining with real traffic and attacks. This paper attempts a practical approach
  • Keywords
    security of data; denial-of service attack; intrusion detection; network administration; Autocorrelation; Estimation theory; Home appliances; Intrusion detection; Marine technology; Needles; Probability; Radar detection; Switches; Time measurement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks, Proceedings 2006 31st IEEE Conference on
  • Conference_Location
    Tampa, FL
  • ISSN
    0742-1303
  • Print_ISBN
    1-4244-0418-5
  • Electronic_ISBN
    0742-1303
  • Type

    conf

  • DOI
    10.1109/LCN.2006.322016
  • Filename
    4116621