• DocumentCode
    1628865
  • Title

    A flow based anomaly detection system using chi-square technique

  • Author

    Muraleedharan, N. ; Parmar, Arun ; Kumar, Manish

  • Author_Institution
    Comput. Networking & Internet Eng., Centre for Dev. of Adv. Comput. (C-DAC), Bangalore, India
  • fYear
    2010
  • Firstpage
    285
  • Lastpage
    289
  • Abstract
    Various tools, which are capable to evade different security mechanisms like firewall, IDS and IPS, exist and that helps the intruders for sending malicious traffic to the network or system. So, inspection of malicious traffic and identification of anomalous activity is very much essential to stop future activity of intruders which can be a possible attack. In this paper we present a flow based system to detect anomalous activity by using IP flow characteristics with chi-square detection mechanism. This system provides solution to identify anomalous activities like scan and flood attack by means of automatic behavior analysis of the network traffic and also give detailed information of attacker, victim, type and time of the attack which can be used for corresponding defense. Anomaly Detection capability of the proposed system is compared with SNORT Intrusion detection system and results prove the very high detection rate of the system over SNORT for different scan and flood attack. The proposed system detects different stealth scan and malformed packets scan. Since the probability of using stealth scan in real attack is very high, this system can identify the real attacks in the initial stage itself and preventive action can be taken.
  • Keywords
    security of data; IDS; IPS; SNORT intrusion detection system; automatic behavior analysis; chi-square technique; firewall; flow based anomaly detection system; intrusion detection; malicious traffic; network traffic; security mechanisms; Computer networks; Floods; High-speed networks; IP networks; Information analysis; Inspection; Intrusion detection; Monitoring; Protocols; Telecommunication traffic; Anomaly detection; chi-square; flow; scan detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advance Computing Conference (IACC), 2010 IEEE 2nd International
  • Conference_Location
    Patiala
  • Print_ISBN
    978-1-4244-4790-9
  • Electronic_ISBN
    978-1-4244-4791-6
  • Type

    conf

  • DOI
    10.1109/IADCC.2010.5422996
  • Filename
    5422996