DocumentCode :
3178802
Title :
Therminator 2: a thermodynamics-based method for real-time patternless intrusion detection
Author :
Donald, Stephen D. ; Mcmillen, Robert V. ; Ford, David K. ; McEachen, John C.
Author_Institution :
Dept. of Electr. & Comput. Eng., Naval Postgraduate Sch., Monterey, CA, USA
Volume :
2
fYear :
2002
fDate :
7-10 Oct. 2002
Firstpage :
1498
Abstract :
A novel system for conducting nonsignature based, or patternless, intrusion detection of computer networks is presented. The initial prototype has been installed at USA Pacific Command and Army Signal Command. This system uses principles of thermodynamics to model network conversation characteristics. Observing the properties of entropy, energy and temperature within the system develops a notion of baseline operating conditions. Perturbations in these properties are considered potential intrusions for further investigation. System functions are decomposed into a network sensing device, a real-time processing component and a forensics component. State definitions for a variety of conditions are discussed. Finally, examples of valid intrusions and other network perturbations in real traffic collected in network operation center backbones are presented. Preliminary results indicate this system has significant potential for revealing anomalies in large network systems.
Keywords :
computer network management; entropy; military communication; military computing; telecommunication security; thermodynamics; Therminator 2; USA Pacific Command and Army Signal Command; computer networks; energy; entropy; forensics component; network conversation characteristics; network operation center backbones; network perturbations; network sensing device; nonsignature based intrusion detection; real-time patternless intrusion detection; real-time processing component; state definitions; temperature; thermodynamics-based method; Computer networks; Entropy; Forensics; Intrusion detection; Prototypes; Real time systems; Spine; Telecommunication traffic; Temperature sensors; Thermodynamics;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
MILCOM 2002. Proceedings
Print_ISBN :
0-7803-7625-0
Type :
conf
DOI :
10.1109/MILCOM.2002.1179705
Filename :
1179705
Link To Document :
بازگشت