DocumentCode :
2779515
Title :
Visualization and Explanation of Payload-Based Anomaly Detection
Author :
Rieck, Konrad ; Laskov, Pavel
fYear :
2009
fDate :
9-10 Nov. 2009
Firstpage :
29
Lastpage :
36
Abstract :
The threat posed by modern network attacks requires novel means for detection of intrusions, as regular signature-based systems fail to cope with the amount and diversity of attacks. Recently, several methods for detection of anomalies in network payloads have been proposed to counteract this threat and identify novel attacks during their initial propagation. However, intrusion detection systems must not only flag malicious events but also provide information needed for assessment of security incidents. Previous work on payload-based anomaly detection has largely ignored this need for explainable decisions. In this paper, we present instruments for visualization and explanation of anomaly detection which can guide the decisions of a security operator. In particular, we propose two techniques: feature differences, for identifying relevant string features of detected anomalies, and feature shading, for highlighting of anomalous contents in network payloads. Both techniques are empirically evaluated using real attacks and network traces, whereby their ability to emphasize typical patterns of attacks is demonstrated.
Keywords :
Computer networks; Computer security; Computer vision; Data security; Information security; Instruments; Intrusion detection; Machine learning; Payloads; Visualization; anomaly detection; network intrusion detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Network Defense (EC2ND), 2009 European Conference on
Conference_Location :
Milano, Italy
Print_ISBN :
978-1-4244-6049-6
Type :
conf
DOI :
10.1109/EC2ND.2009.12
Filename :
5494337
Link To Document :
بازگشت