• DocumentCode
    3178802
  • Title

    Therminator 2: a thermodynamics-based method for real-time patternless intrusion detection

  • Author

    Donald, Stephen D. ; Mcmillen, Robert V. ; Ford, David K. ; McEachen, John C.

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Naval Postgraduate Sch., Monterey, CA, USA
  • Volume
    2
  • fYear
    2002
  • fDate
    7-10 Oct. 2002
  • Firstpage
    1498
  • Abstract
    A novel system for conducting nonsignature based, or patternless, intrusion detection of computer networks is presented. The initial prototype has been installed at USA Pacific Command and Army Signal Command. This system uses principles of thermodynamics to model network conversation characteristics. Observing the properties of entropy, energy and temperature within the system develops a notion of baseline operating conditions. Perturbations in these properties are considered potential intrusions for further investigation. System functions are decomposed into a network sensing device, a real-time processing component and a forensics component. State definitions for a variety of conditions are discussed. Finally, examples of valid intrusions and other network perturbations in real traffic collected in network operation center backbones are presented. Preliminary results indicate this system has significant potential for revealing anomalies in large network systems.
  • Keywords
    computer network management; entropy; military communication; military computing; telecommunication security; thermodynamics; Therminator 2; USA Pacific Command and Army Signal Command; computer networks; energy; entropy; forensics component; network conversation characteristics; network operation center backbones; network perturbations; network sensing device; nonsignature based intrusion detection; real-time patternless intrusion detection; real-time processing component; state definitions; temperature; thermodynamics-based method; Computer networks; Entropy; Forensics; Intrusion detection; Prototypes; Real time systems; Spine; Telecommunication traffic; Temperature sensors; Thermodynamics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    MILCOM 2002. Proceedings
  • Print_ISBN
    0-7803-7625-0
  • Type

    conf

  • DOI
    10.1109/MILCOM.2002.1179705
  • Filename
    1179705