• DocumentCode
    2643188
  • Title

    Cross-level behavioral analysis for robust early intrusion detection

  • Author

    Hsiao, Shun-Wen ; Sun, Yeali S. ; Chen, Meng Chang ; Zhang, Hui

  • Author_Institution
    Dept. of Inf. Manage., Nat. Taiwan Univ., Taipei, Taiwan
  • fYear
    2010
  • fDate
    23-26 May 2010
  • Firstpage
    95
  • Lastpage
    100
  • Abstract
    We anticipate future attacks would evolve to become more sophisticated to outwit existing intrusion detection techniques. Existing anomaly analysis techniques and signature-based detection practices can no longer effective. We believe intrusion detection systems (IDSs) of the future will need to be capable to detect or infer attacks based on more valuable information from the network-related properties and characteristics. We observed that even though the signatures or traffic patterns of future stealthy attacks can be modified to outwit current IDSs, certain behavioral aspects of an attack are invariant. We propose a novel approach that jointly monitors network activities at three different levels: transport layer protocols, (vulnerable) network services, and invariant anomaly behaviors (called attack symptoms). Our system, SecMon, captures the network behaviors by simultaneously performing cross-level state correlation for effective detection of anomaly behaviors. For the most part, the invariant anomaly behavior has not been fully exploited in the past. A probabilistic attack inference model is also proposed for attack assessment by correlating the observed attack symptoms to achieve the low false alarm rate. The evaluations demonstrate our prototype system is efficient and effective for sophisticated attacks, including polymorphism, stealthy, and unknown attack.
  • Keywords
    Computer networks; Computer worms; IP networks; Information analysis; Information management; Information science; Intrusion detection; Robustness; Sun; Telecommunication traffic; Anomaly Detection; Attack Assessment; Cross-Level Behaviorial Analysis; Finite State Machine; Network Protocol;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligence and Security Informatics (ISI), 2010 IEEE International Conference on
  • Conference_Location
    Vancouver, BC, Canada
  • Print_ISBN
    978-1-4244-6444-9
  • Type

    conf

  • DOI
    10.1109/ISI.2010.5484768
  • Filename
    5484768