Title :
Anomaly detection system based on analysis of packet header and payload histograms
Author :
Hareesh, I. ; Prasanna, S. ; Vijayalakshmi, M. ; Shalinie, S. Mercy
Author_Institution :
Dept. of Comput. Sci. & Eng., Thiagarajar Coll. of Eng., Madurai, India
Abstract :
Now a day´s computer networks are very popular, so network attacks are inevitable. As a consequence, any complete security package includes a network Intrusion Detection System (nIDS). This work focuses on nIDSs which work by scanning the network traffic. We have combined classifiers based on packet header information with classifiers based on payload distribution to increase detection rates in non-flood attacks. We have divided packet processing into two parts as header information processing and payload processing. In header information processing we select features from packet header and create model for normal behavior with histograms, then find out the deviation from created models and classify the network traffic. In payload processing we create models of normal payload by generating histograms of payload ASCII distribution and find deviation from created models and classify traffic. Our work differs from previous anomaly based detection techniques by creating histograms for both network header features and for payload of packet, so that our detection system identifies both flooding attacks and non flooding attacks efficiently.
Keywords :
Internet; computer network security; telecommunication traffic; Internet; anomaly detection system; computer networks; detection rates; flooding attacks; header information processing; nIDS; network attacks; network intrusion detection system; network traffic; nonflood attacks; packet header analysis; payload ASCII distribution; payload histograms; security package; Computational modeling; Feature extraction; Histograms; IP networks; Internet; Intrusion detection; Payloads; Anomaly Detection System; Attacks; histograms;
Conference_Titel :
Recent Trends in Information Technology (ICRTIT), 2011 International Conference on
Conference_Location :
Chennai, Tamil Nadu
Print_ISBN :
978-1-4577-0588-5
DOI :
10.1109/ICRTIT.2011.5972283