Title of article :
Moving Dispersion Method for Statistical Anomaly Detection in Intrusion Detection Systems
Author/Authors :
Golic, Jovan Dj. Security Innovation, Italy
From page :
71
To page :
91
Abstract :
A unied method for statistical anomaly detection in intrusion detectionsystems is theoretically introduced. It is based on estimating a dispersion measure of numerical or symbolic data on successive moving windows in time and nding the times when a relative change of the dispersion measureis signicant. Appropriate dispersion measures, relative differences, moving windows, as well as techniques for their effcient estimation are proposed. Inparticular, the method can be used for detecting network traffic anomalies dueto network failures and network attacks such as (distributed) denial of service attacks, scanning attacks, SPAM and SPIT attacks, and massive malicious software attacks.
Keywords :
Intrusion detection , Statisticalanomaly detection , Dispersionmeasure , Concentration measure , Variance , Linear regression , EWMA techniques
Journal title :
ISeCure - The ISC International Journal of Information Security
Journal title :
ISeCure - The ISC International Journal of Information Security
Record number :
2542688
Link To Document :
بازگشت