DocumentCode :
3523176
Title :
An Instant Messaging Intrusion Detection System Framework: Using character frequency analysis for authorship identification and validation
Author :
Orebaugh, Angela
Author_Institution :
Chief Scientist, Securityknox. Email: angela@securityknox.com
fYear :
2006
fDate :
Oct. 2006
Firstpage :
160
Lastpage :
172
Abstract :
The medium of instant messaging (IM) is a well-established means of fast and effective communication. However, a framework for analysis of instant messaging has gone largely unexplored until now. This paper explores instant messaging authorship identification and validation in terms of an author profiling framework and an anomaly-based intrusion detection system (IDS). The framework includes author behavior categories, which are the set of characteristics that remain relatively constant for a large number of messages written by the author. Specific topics include user pattern analysis, user profiling, categorization, computational linguistics, data mining, and anomaly detection. The experiments focus on applying character frequency analysis to IM messages for authorship identification and validation. This addresses the questions; can we identify an author of an IM conversation based strictly on user behavior, do different conversations with a single user look similar, do conversations with different users look different, and what is the demarcation between similar and different? Another experiment focuses on applying an instance-based learning algorithm to the character frequency of IM user messages for authorship identification and validation. The experiment applies the nearest-neighbor classification method to classify messages. It also calculates a degree of confidence to validate the identity of the IM user
Keywords :
Internet; authorisation; electronic messaging; learning systems; pattern classification; telecommunication security; anomaly detection; author profiling; authorship identification; authorship validation; character frequency analysis; computational linguistics; data mining; instance-based learning; instant messaging; intrusion detection system; nearest-neighbor classification; user behavior; user categorization; user pattern analysis; user profiling; Communication effectiveness; Computer crime; Data mining; Forensics; Frequency; Humans; Intrusion detection; Pattern analysis; Social network services; Writing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Carnahan Conferences Security Technology, Proceedings 2006 40th Annual IEEE International
Conference_Location :
Lexington, KY
Print_ISBN :
1-4244-0174-7
Type :
conf
DOI :
10.1109/CCST.2006.313445
Filename :
4105332
Link To Document :
بازگشت