• DocumentCode
    2295039
  • Title

    Changing Network Behavior

  • Author

    Koch, Robert

  • Author_Institution
    Fac. of Comput. Sci., Univ. der Bundeswehr, Munich, Germany
  • fYear
    2009
  • fDate
    19-21 Oct. 2009
  • Firstpage
    60
  • Lastpage
    66
  • Abstract
    The security of computer networks has been in the focus of research for years. While several sophisticated systems had been developed in the area of intrusion detection, new challenges arised. Pattern matching systems are not able to cope with high bandwidth (10 Gbps +) when analyzing the whole payload. Furthermore, new attack schemes arise by increasingly complex software and systems. New approaches like network behavior analyses (NBA) systems show promise for being able to cope with the new threats. These systems evaluate statistical flow data generated from the traffic of the monitored network. While originally designed for optimising traffic handling and accounting in the network, flow data appeared to be powerful for intrusion detection. NBA Systems based on machine learning techniques are able to evaluate these data and to recognize anomalies in the network. However, these systems suffer from a long-lasting learning phase and are susceptible to manipulations during that time. To overcome these shortcomings, we are introducing a fast-learning modular neural network based on pre-processed components. For the development of the new system, the possible attacks on NBA systems have to be investigated and understood in depth.
  • Keywords
    computer networks; learning (artificial intelligence); neural nets; pattern matching; statistical analysis; telecommunication security; telecommunication traffic; NBA system; computer network security; fast-learning modular neural network; intrusion detection; long-lasting learning phase; machine learning technique; monitored network traffic handling; network behavior analysis; network behavior changing; pattern matching system; pre-processed component; statistical flow data; Bandwidth; Computer networks; Computer security; Intrusion detection; Monitoring; Pattern analysis; Pattern matching; Payloads; Software systems; Telecommunication traffic; Fast Learning ANN; IDS; Modular Neural Networks; NBA; NetFlow; sFlow;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security, 2009. NSS '09. Third International Conference on
  • Conference_Location
    Gold Coast, QLD
  • Print_ISBN
    978-1-4244-5087-9
  • Electronic_ISBN
    978-0-7695-3838-9
  • Type

    conf

  • DOI
    10.1109/NSS.2009.55
  • Filename
    5318983