DocumentCode :
3255087
Title :
A two-stage aggregation/thresholding scheme for multi-model anomaly-based approaches
Author :
Tabia, Karim ; Benferhat, Salem ; Djouadi, Yassine
Author_Institution :
Artois Univ.
fYear :
2008
fDate :
14-17 Oct. 2008
Firstpage :
919
Lastpage :
926
Abstract :
This paper deals with anomaly score aggregation and thresholding in multi-model anomaly-based approaches which require multiple detection models and profiles in order to characterize the different aspects of normal activities. Most works focus on profile/model definition while critical issues related to anomaly measuring, aggregating and thresholding have not received similar attention. In this paper, we in particular address the issue of anomaly scoring and aggregating which is a recurring problem in multi-model anomaly-based approaches. We propose a two stage aggregation/thresholding scheme particularly suitable for multi-model anomaly-based approaches. The basic idea of our scheme is the fact that anomalous behaviors induce either intramodel anomalies or inter-model ones. Our scheme is designed for real-time detection of both intra-model and inter-model anomalies. More precisely, we propose local thresholding in order to detect intra-model anomalies and use a Bayesian network in order to, on one hand, extract inter-model regularities and serve, on the other hand, as an aggregating function for computing the overall anomaly score associated with each analyzed audit event. Our experimental studies, carried out on recent and real http traffic, show for instance that most Web-based attacks induce only intra-model anomalies and can be effectively detected in real-time. Moreover, this scheme significantly improves the detection rate of Web-based attacks involving inter-model anomalies.
Keywords :
Web sites; security of data; aggregating function; anomaly score aggregation; multi-model anomaly-based approaches; two-stage aggregation/thresholding scheme; Bayesian methods; Computer networks; Computer science; Event detection; Information analysis; Information systems; Intrusion detection; Real time systems; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Local Computer Networks, 2008. LCN 2008. 33rd IEEE Conference on
Conference_Location :
Montreal, Que
Print_ISBN :
978-1-4244-2412-2
Electronic_ISBN :
978-1-4244-2413-9
Type :
conf
DOI :
10.1109/LCN.2008.4664304
Filename :
4664304
Link To Document :
بازگشت