DocumentCode :
1719033
Title :
Needles in Haystacks: Practical Intrusion Detection from Theoretical Results
Author :
Marin, Gerald A. ; Allen, William H.
Author_Institution :
Florida Inst. of Technol.
fYear :
2006
Firstpage :
571
Lastpage :
573
Abstract :
Many researchers are working towards discovering techniques that can alert network administrators to the presence of previously unseen attacks in their networks. Here we focus on attacks, such as denial-of service attacks, that depend on multiple packets being sent over minutes or, at least, several seconds. No definitive technique has been demonstrated that can guarantee a substantial probability of detection while keeping probability of false alarm at an acceptable level. However, theoretical work by Li, Jia, and Zhao (referenced below) describes an interesting approach based on observing changes to autocorrelations obtained over time from measured traffic. Their work provides a theoretical way of estimating probability of detection vs. probability of false alarm. They make assumptions concerning availability of a background template and normality of residuals that bear examining with real traffic and attacks. This paper attempts a practical approach
Keywords :
security of data; denial-of service attack; intrusion detection; network administration; Autocorrelation; Estimation theory; Home appliances; Intrusion detection; Marine technology; Needles; Probability; Radar detection; Switches; Time measurement;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Local Computer Networks, Proceedings 2006 31st IEEE Conference on
Conference_Location :
Tampa, FL
ISSN :
0742-1303
Print_ISBN :
1-4244-0418-5
Electronic_ISBN :
0742-1303
Type :
conf
DOI :
10.1109/LCN.2006.322016
Filename :
4116621
Link To Document :
بازگشت