• DocumentCode
    3432800
  • Title

    Fates: A Granular Approach to Real-Time Anomaly Detection

  • Author

    Janies, Jeff ; Huang, Chin-Tser

  • Author_Institution
    Univ. of South Carolina, Columbia
  • fYear
    2007
  • fDate
    13-16 Aug. 2007
  • Firstpage
    605
  • Lastpage
    610
  • Abstract
    Anomaly-based intrusion detection systems have the ability of detecting novel attacks, but in real-time detection, they face the challenges of producing many false alarms and failing to contend with the high speed of modern networks due to their computationally demanding algorithms. In this paper, we present Fates, an anomaly-based NIDS designed to alleviate the two challenges. Fates views the monitored network as a collection of individual hosts instead of as a single autonomous entity and uses dynamic, individual threshold for each monitored host, such that it can differentiate between characteristics of individual hosts and independently assess their threat to the network. Each packet to and from a monitored host is analyzed with an adaptive and efficient charging scheme that considers the packet´s type, number of occurrences, source, and destination. The resulting charge is applied to the individual hosts´ threat assessment, providing pinpointed analysis of anomalous activities. We use various datasets to validate Fates´s ability to distinguish scanning behavior from benign traffic in real time.
  • Keywords
    computer network management; real-time systems; telecommunication security; telecommunication traffic; Fates real-time anomaly-based network intrusion detection system; network host monitoring; network traffic; real-time anomaly detection; Computer science; Entropy; Face detection; Intrusion detection; Large-scale systems; Monitoring; Real time systems; Signal detection; Telecommunication traffic; Traffic control; Anomaly-based Detection; Network-based Intrusion Detection System;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2007. ICCCN 2007. Proceedings of 16th International Conference on
  • Conference_Location
    Honolulu, HI
  • ISSN
    1095-2055
  • Print_ISBN
    978-1-4244-1251-8
  • Electronic_ISBN
    1095-2055
  • Type

    conf

  • DOI
    10.1109/ICCCN.2007.4317884
  • Filename
    4317884