DocumentCode :
1511285
Title :
Training a neural-network based intrusion detector to recognize novel attacks
Author :
Lee, Susan C. ; Heinbuch, David V.
Author_Institution :
Appl. Phys. Lab., Johns Hopkins Univ., Laurel, MD, USA
Volume :
31
Issue :
4
fYear :
2001
fDate :
7/1/2001 12:00:00 AM
Firstpage :
294
Lastpage :
299
Abstract :
While many commercial intrusion detection systems (IDS) are deployed, the protection they afford is modest. State-of-the-art IDS produce voluminous alerts, most false alarms, and function mainly by recognizing the signatures of known attacks so that novel attacks slip past them. Attempts have been made to create systems that recognize the signature of “normal,” in the hope that they will then detect attacks, known or novel. These systems are often confounded by the extreme variability of nominal behavior. The paper describes an experiment with an IDS composed of a hierarchy of neural networks (NN) that functions as a true anomaly detector. This result is achieved by monitoring selected areas of network behavior, such as protocols, that are predictable in advance. While this does not cover the entire attack space, a considerable number of attacks are carried out by violating the expectations of the protocol/operating system designer. Within this focus, the NNs are trained using data that spans the entire normal space. These detectors are able to recognize attacks that were not specifically presented during training. We show that using small detectors in a hierarchy gives a better result than a single large detector. Some techniques can be used not only to detect anomalies, but to distinguish among them
Keywords :
backpropagation; pattern recognition; protocols; security of data; self-organising feature maps; telecommunication security; anomaly detector; network behavior; neural-network based intrusion detector; nominal behavior; novel attacks; Databases; Detectors; Intrusion detection; Monitoring; Neural networks; Operating systems; Pattern recognition; Protection; Protocols; Testing;
fLanguage :
English
Journal_Title :
Systems, Man and Cybernetics, Part A: Systems and Humans, IEEE Transactions on
Publisher :
ieee
ISSN :
1083-4427
Type :
jour
DOI :
10.1109/3468.935046
Filename :
935046
Link To Document :
بازگشت