• DocumentCode
    3080727
  • Title

    Information-Theoretic Detection of Masquerade Mimicry Attacks

  • Author

    Tapiador, Juan E. ; Clark, John A.

  • Author_Institution
    Dept. of Comput. Sci., Univ. of York, York, UK
  • fYear
    2010
  • fDate
    1-3 Sept. 2010
  • Firstpage
    183
  • Lastpage
    190
  • Abstract
    In a masquerade attack, an adversary who has stolen a legitimate user´s credentials attempts to impersonate him to carry out malicious actions. Automatic detection of such attacks is often undertaken constructing models of normal behaviour of each user and then measuring significant departures from them. One potential vulnerability of this approach is that anomaly detection algorithms are generally susceptible of being deceived. In this paper, we first investigate how a resourceful masquerader can successfully evade detection while still accomplishing his goals. We then propose an algorithm based on the Kullback-Leibler divergence which attempts to identify if a sufficiently anomalous attack is present within an apparently normal request. Our experimental results indicate that the proposed scheme achieves considerably better detection quality than adversarial-unaware approaches.
  • Keywords
    entropy; probability; security of data; Kullback-Leibler divergence; automatic malicious attack detection; masquerade mimicry attack; Computational modeling; Context; Detection algorithms; Detectors; Government; Security; Training; Anomaly detection; Kullback-Leibler divergence; insider threats; masqueraders; mimicry attacks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security (NSS), 2010 4th International Conference on
  • Conference_Location
    Melbourne, VIC
  • Print_ISBN
    978-1-4244-8484-3
  • Electronic_ISBN
    978-0-7695-4159-4
  • Type

    conf

  • DOI
    10.1109/NSS.2010.55
  • Filename
    5635526