DocumentCode
2295039
Title
Changing Network Behavior
Author
Koch, Robert
Author_Institution
Fac. of Comput. Sci., Univ. der Bundeswehr, Munich, Germany
fYear
2009
fDate
19-21 Oct. 2009
Firstpage
60
Lastpage
66
Abstract
The security of computer networks has been in the focus of research for years. While several sophisticated systems had been developed in the area of intrusion detection, new challenges arised. Pattern matching systems are not able to cope with high bandwidth (10 Gbps +) when analyzing the whole payload. Furthermore, new attack schemes arise by increasingly complex software and systems. New approaches like network behavior analyses (NBA) systems show promise for being able to cope with the new threats. These systems evaluate statistical flow data generated from the traffic of the monitored network. While originally designed for optimising traffic handling and accounting in the network, flow data appeared to be powerful for intrusion detection. NBA Systems based on machine learning techniques are able to evaluate these data and to recognize anomalies in the network. However, these systems suffer from a long-lasting learning phase and are susceptible to manipulations during that time. To overcome these shortcomings, we are introducing a fast-learning modular neural network based on pre-processed components. For the development of the new system, the possible attacks on NBA systems have to be investigated and understood in depth.
Keywords
computer networks; learning (artificial intelligence); neural nets; pattern matching; statistical analysis; telecommunication security; telecommunication traffic; NBA system; computer network security; fast-learning modular neural network; intrusion detection; long-lasting learning phase; machine learning technique; monitored network traffic handling; network behavior analysis; network behavior changing; pattern matching system; pre-processed component; statistical flow data; Bandwidth; Computer networks; Computer security; Intrusion detection; Monitoring; Pattern analysis; Pattern matching; Payloads; Software systems; Telecommunication traffic; Fast Learning ANN; IDS; Modular Neural Networks; NBA; NetFlow; sFlow;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security, 2009. NSS '09. Third International Conference on
Conference_Location
Gold Coast, QLD
Print_ISBN
978-1-4244-5087-9
Electronic_ISBN
978-0-7695-3838-9
Type
conf
DOI
10.1109/NSS.2009.55
Filename
5318983
Link To Document