DocumentCode
2643188
Title
Cross-level behavioral analysis for robust early intrusion detection
Author
Hsiao, Shun-Wen ; Sun, Yeali S. ; Chen, Meng Chang ; Zhang, Hui
Author_Institution
Dept. of Inf. Manage., Nat. Taiwan Univ., Taipei, Taiwan
fYear
2010
fDate
23-26 May 2010
Firstpage
95
Lastpage
100
Abstract
We anticipate future attacks would evolve to become more sophisticated to outwit existing intrusion detection techniques. Existing anomaly analysis techniques and signature-based detection practices can no longer effective. We believe intrusion detection systems (IDSs) of the future will need to be capable to detect or infer attacks based on more valuable information from the network-related properties and characteristics. We observed that even though the signatures or traffic patterns of future stealthy attacks can be modified to outwit current IDSs, certain behavioral aspects of an attack are invariant. We propose a novel approach that jointly monitors network activities at three different levels: transport layer protocols, (vulnerable) network services, and invariant anomaly behaviors (called attack symptoms). Our system, SecMon, captures the network behaviors by simultaneously performing cross-level state correlation for effective detection of anomaly behaviors. For the most part, the invariant anomaly behavior has not been fully exploited in the past. A probabilistic attack inference model is also proposed for attack assessment by correlating the observed attack symptoms to achieve the low false alarm rate. The evaluations demonstrate our prototype system is efficient and effective for sophisticated attacks, including polymorphism, stealthy, and unknown attack.
Keywords
Computer networks; Computer worms; IP networks; Information analysis; Information management; Information science; Intrusion detection; Robustness; Sun; Telecommunication traffic; Anomaly Detection; Attack Assessment; Cross-Level Behaviorial Analysis; Finite State Machine; Network Protocol;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligence and Security Informatics (ISI), 2010 IEEE International Conference on
Conference_Location
Vancouver, BC, Canada
Print_ISBN
978-1-4244-6444-9
Type
conf
DOI
10.1109/ISI.2010.5484768
Filename
5484768
Link To Document