DocumentCode :
2255194
Title :
Benchmarking anomaly-based detection systems
Author :
Maxion, Roy A. ; Tan, Kymie M C
Author_Institution :
Dept. of Comput. Sci., Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear :
2000
fDate :
2000
Firstpage :
623
Lastpage :
630
Abstract :
Anomaly detection is a key element of intrusion detection and other detection systems in which perturbations of normal behavior suggest the presence of intentionally or unintentionally induced attacks, faults, defects, etc. Because most anomaly detectors are based on probabilistic algorithms that exploit the intrinsic structure (or regularity) embedded in data logs, a fundamental question is whether or not such structure influences detection performance. If detector performance is indeed a function of environmental regularity, it would be critical to match detectors to environmental characteristics. In intrusion-detection settings, however, this is not done, possibly because such characteristics are not easily ascertained. This paper introduces a metric for characterizing structure in data environments, and tests the hypothesis that intrinsic structure influences probabilistic detection. In a series of experiments, an anomaly detection algorithm was applied to a benchmark suite of 165 carefully calibrated, anomaly-injected data sets of varying structure. The results showed performance differences of as much as an order of magnitude, indicating that current approaches to anomaly detection may not be universally dependable
Keywords :
calibration; failure analysis; security of data; software performance evaluation; anomaly-based detection systems; attacks; benchmarking; calibrated anomaly-injected data sets; computer security; data environment structure characterization; data logs; defects; dependability; detection performance; empirical methods; environmental regularity; faults; intrusion detection; performance; probabilistic detection algorithms; system behaviour perturbations; Application software; Benchmark testing; Bridges; Computer science; Computer security; Detectors; Electrocardiography; Fault detection; Intrusion detection; Plasma applications;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks, 2000. DSN 2000. Proceedings International Conference on
Conference_Location :
New York, NY
Print_ISBN :
0-7695-0707-7
Type :
conf
DOI :
10.1109/ICDSN.2000.857599
Filename :
857599
Link To Document :
بازگشت