• DocumentCode
    3097432
  • Title

    A Network Access Control Mechanism Based on Behavior Profiles

  • Author

    Frias-Martinez, Vanessa ; Sherrick, Joseph ; Stolfo, Salvatore J. ; Keromytis, Angelos D.

  • Author_Institution
    Telefonica Res., Madrid, Spain
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    3
  • Lastpage
    12
  • Abstract
    Current network access control (NAC) technologies manage the access of new devices into a network to prevent rogue devices from attacking network hosts or services. Typically, new devices are checked against a set of manually defined policies (rules) before being granted access by the NAC enforcer. The main difficulty with this approach lies in the generation and update of new policies manually as time elapses and all devices have to reestablish their access rights. The BB-NAC mechanism was the first to introduce a novel behavior-based network access control architecture based on behavior profiles and not rules, where behavior-based access control policies were automatically generated. As originally presented, BB-NAC relied on manually pre-determined clusters of behavior which required human intervention and prevented the fully automation of the mechanism. In this paper, we present an enhanced BB-NAC mechanism that fully automatizes the creation of clusters of behavior. The access control is enhanced with the incorporation of automatic behavior clustering, which improves the intrusion detection capabilities by allowing for a more fine-grained definition of normal behavior. Apart from the lack of automatic clustering, the original BB-NAC overlooked the evolution of the mechanism as new behavior profiles were computed over time. As part of our enhancements, we also present an incremental-learning algorithm that automatically updates the behavior-based access control policies. We show that the algorithm is resilient to compromised or fabricated profiles trying to manipulate the policies. We provide extensive experiments with real user profiles computed with their network flows processed from Cisco NetFlow logs captured at our host institution. Our results show that behavior-based access control policies enhance conventional NAC technologies. Specifically, we achieve true rejection rates of 95% for anomalous user profiles separated by one standard deviation from the nor- mal user network behavior. In addition, we also show that the enhanced mechanism can differentiate between normal changes in the behavior profiles (concept drift) and attacks.
  • Keywords
    authorisation; computer network management; computer network security; learning (artificial intelligence); BB-NAC mechanism; Cisco NetFlow; anomalous user profiles; automatic behavior clustering; behavior profiles; behavior-based network access control architecture; incremental-learning algorithm; intrusion detection capability; network access control mechanism; network flows; network hosts; network services; rogue devices; Access control; Application software; Clustering algorithms; Communication system traffic control; Computer architecture; Computer networks; Humans; Network servers; Permission; Software performance; Anomaly Detection; Behavior-based Network Access Control; Concept Drift in Data Streams; Network Intrusion Prevention;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.10
  • Filename
    5380530