DocumentCode :
1511269
Title :
Probabilistic techniques for intrusion detection based on computer audit data
Author :
Ye, Nong ; Li, Xiangyang ; Chen, Qiang ; Emran, Syed Masum ; Xu, Mingming
Author_Institution :
Inf. & Syst. Assurance Lab., Arizona State Univ., Tempe, AZ, USA
Volume :
31
Issue :
4
fYear :
2001
fDate :
7/1/2001 12:00:00 AM
Firstpage :
266
Lastpage :
274
Abstract :
This paper presents a series of studies on probabilistic properties of activity data in an information system for detecting intrusions into the information system. Various probabilistic techniques of intrusion detection, including decision tree, Hotelling´s T2 test, chi-square multivariate test, and Markov chain are applied to the same training set and the same testing set of computer audit data for investigating the frequency property and the ordering property of computer audit data. The results of these studies provide answers to several questions concerning which properties are critical to intrusion detection. First, our studies show that the frequency property of multiple audit event types in a sequence of events is necessary for intrusion detection. A single audit event at a given time is not sufficient for intrusion detection. Second, the ordering property of multiple audit events provides additional advantage to the frequency property for intrusion detection. However, unless the scalability problem of complex data models taking into account the ordering property of activity data is solved, intrusion detection techniques based on the frequency property provide a viable solution that produces good intrusion detection performance with low computational overhead
Keywords :
Markov processes; auditing; decision trees; information systems; probability; security of data; Hotelling T2 test; Markov chain; activity data; chi-square multivariate test; complex data models; computer audit data; decision tree; event sequence; frequency property; information system; intrusion detection; low computational overhead; multiple audit event types; probabilistic techniques; Computer bugs; Decision trees; Frequency; Information systems; Intrusion detection; Laboratories; Pattern matching; Pattern recognition; Telecommunication traffic; Testing;
fLanguage :
English
Journal_Title :
Systems, Man and Cybernetics, Part A: Systems and Humans, IEEE Transactions on
Publisher :
ieee
ISSN :
1083-4427
Type :
jour
DOI :
10.1109/3468.935043
Filename :
935043
Link To Document :
بازگشت