DocumentCode
1719033
Title
Needles in Haystacks: Practical Intrusion Detection from Theoretical Results
Author
Marin, Gerald A. ; Allen, William H.
Author_Institution
Florida Inst. of Technol.
fYear
2006
Firstpage
571
Lastpage
573
Abstract
Many researchers are working towards discovering techniques that can alert network administrators to the presence of previously unseen attacks in their networks. Here we focus on attacks, such as denial-of service attacks, that depend on multiple packets being sent over minutes or, at least, several seconds. No definitive technique has been demonstrated that can guarantee a substantial probability of detection while keeping probability of false alarm at an acceptable level. However, theoretical work by Li, Jia, and Zhao (referenced below) describes an interesting approach based on observing changes to autocorrelations obtained over time from measured traffic. Their work provides a theoretical way of estimating probability of detection vs. probability of false alarm. They make assumptions concerning availability of a background template and normality of residuals that bear examining with real traffic and attacks. This paper attempts a practical approach
Keywords
security of data; denial-of service attack; intrusion detection; network administration; Autocorrelation; Estimation theory; Home appliances; Intrusion detection; Marine technology; Needles; Probability; Radar detection; Switches; Time measurement;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, Proceedings 2006 31st IEEE Conference on
Conference_Location
Tampa, FL
ISSN
0742-1303
Print_ISBN
1-4244-0418-5
Electronic_ISBN
0742-1303
Type
conf
DOI
10.1109/LCN.2006.322016
Filename
4116621
Link To Document