• DocumentCode
    2576299
  • Title

    Anomaly detection system based on analysis of packet header and payload histograms

  • Author

    Hareesh, I. ; Prasanna, S. ; Vijayalakshmi, M. ; Shalinie, S. Mercy

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Thiagarajar Coll. of Eng., Madurai, India
  • fYear
    2011
  • fDate
    3-5 June 2011
  • Firstpage
    412
  • Lastpage
    416
  • Abstract
    Now a day´s computer networks are very popular, so network attacks are inevitable. As a consequence, any complete security package includes a network Intrusion Detection System (nIDS). This work focuses on nIDSs which work by scanning the network traffic. We have combined classifiers based on packet header information with classifiers based on payload distribution to increase detection rates in non-flood attacks. We have divided packet processing into two parts as header information processing and payload processing. In header information processing we select features from packet header and create model for normal behavior with histograms, then find out the deviation from created models and classify the network traffic. In payload processing we create models of normal payload by generating histograms of payload ASCII distribution and find deviation from created models and classify traffic. Our work differs from previous anomaly based detection techniques by creating histograms for both network header features and for payload of packet, so that our detection system identifies both flooding attacks and non flooding attacks efficiently.
  • Keywords
    Internet; computer network security; telecommunication traffic; Internet; anomaly detection system; computer networks; detection rates; flooding attacks; header information processing; nIDS; network attacks; network intrusion detection system; network traffic; nonflood attacks; packet header analysis; payload ASCII distribution; payload histograms; security package; Computational modeling; Feature extraction; Histograms; IP networks; Internet; Intrusion detection; Payloads; Anomaly Detection System; Attacks; histograms;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Recent Trends in Information Technology (ICRTIT), 2011 International Conference on
  • Conference_Location
    Chennai, Tamil Nadu
  • Print_ISBN
    978-1-4577-0588-5
  • Type

    conf

  • DOI
    10.1109/ICRTIT.2011.5972283
  • Filename
    5972283