Title :
Parallel analysis for lightweight network incident detection using nonlinear adaptive systems
Author :
Ando, Ruo ; Takefuji, Yoshiyasu
Author_Institution :
Nat. Inst. of Inf. & Commun. Technol., Tokyo
Abstract :
The rapid increasing of security incidents imposes a great burden on Internet users and system administrators. In this paper we discuss a parallel analysis for lightweight network incident detection using nonlinear adaptive systems. We run AID (anomaly intrusion detection) and MID (misuse intrusion detection) systems in parallel. Two detectors generate binary output misuse = {YES/NO} and anomaly = {YES/NO}. Then, we can determine whether we need to perform network or security operation. We apply clustering algorithm for AID and classification algorithm for MID. The nonlinear adaptive system is trained for running MID and AID in parallel. Proposed parallel system is more lightweight and simple to operate even if the number of incident patterns is increased. Experimental results in the case where false positive is frequently caused show that our method is functional with a recognition rate of attacks less than 10%, while finding the anomaly status. Also, performance evaluation show that proposed system can work with reasonable CPU utilization compared with conventional serial search based system.
Keywords :
Internet; parallel processing; pattern clustering; security of data; telecommunication security; Internet; anomaly intrusion detection system; clustering algorithm; lightweight network security incident detection; misuse intrusion detection system; nonlinear adaptive system; parallel system; performance evaluation; serial search based system; Adaptive systems; Clustering algorithms; Data mining; Data security; Databases; Information security; Intrusion detection; Leak detection; Parallel processing; Web and internet services;
Conference_Titel :
Network and Parallel Computing Workshops, 2007. NPC Workshops. IFIP International Conference on
Conference_Location :
Liaoning
Print_ISBN :
978-0-7695-2943-1
DOI :
10.1109/NPC.2007.83