• DocumentCode
    1566475
  • Title

    Intrusion Detection with Data Correlation Relation Graph

  • Author

    Hassanzadeh, Amin ; Sadeghian, Babak

  • Author_Institution
    Comput. Eng. & IT Dept., Amirkabir Univ. of Technol., Tehran
  • fYear
    2008
  • Firstpage
    982
  • Lastpage
    989
  • Abstract
    Intrusion detection systems are designed based on the assumption that the behavior of an intruder is different from a normal user of a system. We show that intrusion detection can be done based on the assumption that the correlation of system events and parameters is changed during an attack to the system. In this paper, we propose a new method in correlating data and events for "network based intrusion detection systems". When an attack occurs, the correlation of security parameters is changed. We propose to use the state of correlation between parameters to detect an attack. First we show how to select effective security parameters for our detection engine with statistical correlation methods. Then, we propose how to build correlation relation graphs (CRG) for the parameters showing higher correlation. Finally we show how the attack may be detected with comparing the CRG parameter pairs for each session with the deviation from the regression line of them. We present our results for detecting a SynFlood attack with this method. We give also the corresponding detection rate and false alarm rate.
  • Keywords
    correlation methods; graph theory; security of data; statistical analysis; SynFlood attack; data correlation relation graph; intrusion detection systems; security parameters; statistical correlation methods; system events; Availability; Computer security; Correlation; Data engineering; Data security; Engines; Floods; Intrusion detection; Reliability engineering; TCPIP; correlation coefficient; correlation relation graph; data correlation; intrusion detection; regression line; synflood;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-0-7695-3102-1
  • Type

    conf

  • DOI
    10.1109/ARES.2008.119
  • Filename
    4529450