DocumentCode
2399546
Title
Remote attack detection method in IDA: MLSI-based intrusion detection using discriminant analysis
Author
Asak, Midori ; Onabura, Takefumi ; Inoue, Tadashi ; Goto, Shigeki
Author_Institution
Software Technol. Center, Inf.-Technol. Promotion Agency, Tokyo, Japan
fYear
2002
fDate
2002
Firstpage
64
Lastpage
73
Abstract
In order to detect intrusions, IDA (Intrusion Detection Agent system) initially monitors system logs in order to discover an MLSI-which is an certain event which in many cases occurs during an intrusion. If an MLSI is found, then IDA judges whether the MLSI is accompanied by an intrusion. We adopt discriminant analysis to analyze information after IDA detects an MLSI in a remote attack. Discriminant analysis provides a classification function that allows IDA to separate intrusive activities from non-intrusive activities. Using discriminant analysis, we can detect intrusions by analyzing only a part of system calls occurring on a host machine, and we can determine whether an unknown sample is an intrusion. In this paper, we explain in detail how we perform discriminant analysis to detect intrusions, and evaluate the classification function. We also describe how to extract a sample from system logs, which is necessary to implement the discriminant analysis function in IDA
Keywords
security of data; system monitoring; IDA; Intrusion Detection Agent system; MLSI-based intrusion detection; certain event; classification function; discriminant analysis; host machine; remote attack detection method; system calls; system log monitoring; Internet; Intrusion detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Applications and the Internet, 2002. (SAINT 2002). Proceedings. 2002 Symposium on
Conference_Location
Nara
Print_ISBN
0-7695-1447-2
Type
conf
DOI
10.1109/SAINT.2002.994451
Filename
994451
Link To Document