• DocumentCode
    2485305
  • Title

    A data correlation method for anomaly detection systems using regression relations

  • Author

    Hassanzadeh, Amin ; Sadeghiyan, Babak

  • Author_Institution
    Dept. of Comput. Eng., Amirkabir Univ. of Technol., Tehran, Iran
  • fYear
    2009
  • fDate
    14-17 Oct. 2009
  • Firstpage
    242
  • Lastpage
    248
  • Abstract
    Normal profiles have specific properties which would be changed when an attack occurs. The main property we have considered for each behavior is the correlation between the parameters of it. We compute a correlation matrix for normal sessions in the training phase. Then we select effective security parameters for our detection engine using an equivalent class with a graphical illustration namely correlation relation graph (CRG). These extracted parameters among all parameters of each normal behavior have a relation with each other which could be computed by regression relations. Each behavior has some pairs of selected parameters including the independent parameter and the dependent one. As an inline detection process, we look at the value of selected parameters of each current session and put them into their computed regression relation. If the computed value of the dependent parameter of each pair has a value greater then what we compute by their regression relation, it will be considered as a deviation. Number of deviations per session and the combination of them is used to label a session as normal or attack. The results show that our proposed method has suitable detection rate and false alarm.
  • Keywords
    graph theory; matrix algebra; regression analysis; security of data; anomaly detection systems; correlation matrix; correlation relation graph; data correlation method; inline detection process; regression relations; security parameters; Computer networks; Correlation; Data engineering; Data security; Engines; Humans; Information analysis; Information security; Intrusion detection; Sensor systems; Anomaly Detection; Confidence Interval; Correlation Coefficient; Correlation Relation Graph; Data Correlation; Regression Relation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Future Information Networks, 2009. ICFIN 2009. First International Conference on
  • Conference_Location
    Beijing
  • Print_ISBN
    978-1-4244-5158-6
  • Electronic_ISBN
    978-1-4244-5159-3
  • Type

    conf

  • DOI
    10.1109/ICFIN.2009.5339579
  • Filename
    5339579