• DocumentCode
    3040175
  • Title

    Detecting denial-of-service attacks through feature cross-correlation

  • Author

    Zhang, Zheng ; Manikopoulos, Constantine N.

  • Author_Institution
    Dept. of Electr. & Comput. Eng., New Jersey Inst. of Technol., Newark, NJ, USA
  • fYear
    2004
  • fDate
    26-27 Apr 2004
  • Firstpage
    67
  • Lastpage
    70
  • Abstract
    This paper describes CIDS (Correlation Intrusion Detection System), a novel approach in the detection of DoS attacks that utilizes the change in cross-correlation between selected features. As the DOS attack evolves the cross-correlations rise thus revealing the attack. CIDS relies on changes in correlation magnitude upon shifting from normal to attack conditions, thus it is an anomaly type intrusion detection system (IDS). However it is characterized by several advantages over anomaly IDS, primarily due to the fact that it greatly reduces and/or eliminates the need to maintain normal reference profiles. Thus CIDS (1) is algorithmically simple; (2) consumes less computational and storage resources; (3) is faster in execution; (4) promises to be more robust; and, (5) is conceptually simple, thus promises to be easier to maintain. By detecting abnormal conditions, CIDS also promises to detect novel as well as known attacks, an important advantage over signature based systems. Moreover, it achieves satisfactory misclassification rates, as demonstrated by the application of the scheme to the DARPA´98 corpus of intrusion attacks, namely false positive (FP) and false negative (FN) rates of 0 and 0.0605, respectively, and overall missclassification rate of 0.0011.
  • Keywords
    authorisation; computer network management; correlation methods; CIDS; Correlation Intrusion Detection System; DARPA´98 corpus; DoS attacks; anomaly type IDS; computer network; denial-of-service attacks; false negative rates; false positive rates; feature cross-correlation; intrusion detection system; misclassification rates; novel attacks; Computer crime; Computer networks; Condition monitoring; Equations; Gaussian distribution; Intrusion detection; Multidimensional systems; Robustness; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advances in Wired and Wireless Communication, 2004 IEEE/Sarnoff Symposium on
  • Print_ISBN
    0-7803-8219-6
  • Type

    conf

  • DOI
    10.1109/SARNOF.2004.1302842
  • Filename
    1302842