DocumentCode :
3155051
Title :
Packet- vs. session-based modeling for intrusion detection systems
Author :
Caulkins, L. T C Bruce D ; Lee, Joohan ; Wang, Morgan
Author_Institution :
Dept. of Modeling & Simulation, Central Florida Univ., Orlando, FL, USA
Volume :
1
fYear :
2005
fDate :
4-6 April 2005
Firstpage :
116
Abstract :
In today\´s interconnected networks, intrusion detection systems (IDSs), encryption devices, firewalls and other hardware and software solutions are critical in providing complete security solutions for corporations and government agencies. Many IDS variants exist which allow security personnel to identify attack network packets primarily through the use of signature detection where the IDS "recognizes" attack packets due to their well-known signatures as those packets cross the network\´s gateway threshold. However, anomaly-based ID systems identify normal traffic within a network and report abnormal behavior. We report the findings of our research in the area of anomaly-based intrusion detection systems using data-mining techniques to create a decision tree model of our network using the 1999 DARPA intrusion detection evaluation data set. After the model was created, we gathered data from our local campus network and scored the new data through the model using both packet-based and session-based modeling and compare the results.
Keywords :
data mining; decision trees; packet switching; security of data; telecommunication security; DARPA intrusion detection evaluation data set; anomaly-based ID systems; anomaly-based intrusion detection systems; attack network packets; attack packets; data-mining techniques; decision tree model; encryption devices; firewalls; gateway threshold; interconnected networks; local campus network; normal traffic; packet-based modeling; session-based modeling; signature detection; Computer networks; Cryptography; Data security; Detectors; Internet; Intrusion detection; Protection; Radar detection; Telecommunication traffic; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Technology: Coding and Computing, 2005. ITCC 2005. International Conference on
Print_ISBN :
0-7695-2315-3
Type :
conf
DOI :
10.1109/ITCC.2005.222
Filename :
1428447
Link To Document :
بازگشت