DocumentCode
2576299
Title
Anomaly detection system based on analysis of packet header and payload histograms
Author
Hareesh, I. ; Prasanna, S. ; Vijayalakshmi, M. ; Shalinie, S. Mercy
Author_Institution
Dept. of Comput. Sci. & Eng., Thiagarajar Coll. of Eng., Madurai, India
fYear
2011
fDate
3-5 June 2011
Firstpage
412
Lastpage
416
Abstract
Now a day´s computer networks are very popular, so network attacks are inevitable. As a consequence, any complete security package includes a network Intrusion Detection System (nIDS). This work focuses on nIDSs which work by scanning the network traffic. We have combined classifiers based on packet header information with classifiers based on payload distribution to increase detection rates in non-flood attacks. We have divided packet processing into two parts as header information processing and payload processing. In header information processing we select features from packet header and create model for normal behavior with histograms, then find out the deviation from created models and classify the network traffic. In payload processing we create models of normal payload by generating histograms of payload ASCII distribution and find deviation from created models and classify traffic. Our work differs from previous anomaly based detection techniques by creating histograms for both network header features and for payload of packet, so that our detection system identifies both flooding attacks and non flooding attacks efficiently.
Keywords
Internet; computer network security; telecommunication traffic; Internet; anomaly detection system; computer networks; detection rates; flooding attacks; header information processing; nIDS; network attacks; network intrusion detection system; network traffic; nonflood attacks; packet header analysis; payload ASCII distribution; payload histograms; security package; Computational modeling; Feature extraction; Histograms; IP networks; Internet; Intrusion detection; Payloads; Anomaly Detection System; Attacks; histograms;
fLanguage
English
Publisher
ieee
Conference_Titel
Recent Trends in Information Technology (ICRTIT), 2011 International Conference on
Conference_Location
Chennai, Tamil Nadu
Print_ISBN
978-1-4577-0588-5
Type
conf
DOI
10.1109/ICRTIT.2011.5972283
Filename
5972283
Link To Document