DocumentCode
2311287
Title
Noise-Resistant Payload Anomaly Detection for Network Intrusion Detection Systems
Author
Kim, Sun-il ; Nwanze, Nnamdi
Author_Institution
Dept. of Comput. Sci., Univ. of Alabama in Huntsville, Huntsville, AL
fYear
2008
fDate
7-9 Dec. 2008
Firstpage
517
Lastpage
523
Abstract
Anomaly-based intrusion detection systems are an essential part of a global security solution and effectively complement signature-based detection schemes. Its strength in detecting previously unknown and never seen attacks make it attractive, but it is more prone to higher false positives. In this paper, we present a simple payload based intrusion detection scheme that is resilient to contaminated traffic that may unintentionally be used during training. Our results show that, by adjusting the two tuning parameters used in our approach, the ability to detect attacks while maintaining low false positives is not hindered, even when 10% of the training traffic consists of attacks. Test results also show that our approach is not sensitive to changes in the parameters, and a wide range of values can be used to yield high per-packet detection rates (over 99.5%) while keeping false positives low (below 0.3%).
Keywords
security of data; telecommunication security; contaminated traffic; global security solution; high per packet detection rates; network intrusion detection systems; noise resistant payload anomaly detection; signature based detection schemes; tuning parameters; Computer science; Computer security; Computer vision; Databases; Information security; Information technology; Intrusion detection; Payloads; Protection; Telecommunication traffic;
fLanguage
English
Publisher
ieee
Conference_Titel
Performance, Computing and Communications Conference, 2008. IPCCC 2008. IEEE International
Conference_Location
Austin, Texas
ISSN
1097-2641
Print_ISBN
978-1-4244-3368-1
Electronic_ISBN
1097-2641
Type
conf
DOI
10.1109/PCCC.2008.4745080
Filename
4745080
Link To Document