DocumentCode
3255061
Title
Detection of anomalous network packets using lightweight stateless payload inspection
Author
Nwanze, Nnamdi ; Summerville, Douglas
Author_Institution
Dept. of Electr. & Comput. Eng., State Univ. of New York at Binghamton, Binghamton, NY
fYear
2008
fDate
14-17 Oct. 2008
Firstpage
911
Lastpage
918
Abstract
A real-time packet-level anomaly detection approach for high-speed network intrusion prevention is described. The approach is suitable for small and fast hardware implementation and was designed to be embedded in network appliances. Each network packet is characterized using a novel technique that efficiently maps the payload histogram onto a simple pair of features using hypercube hash functions, which were chosen for their implementation efficiency in both hardware and software. This two-dimensional feature space is quantized into a binary bitmap representing the normal and anomalous feature regions. The potential loss of accuracy due to the reduction in feature space is countered by the ability of the bitmaps to capture nearly arbitrary shaped regions in the feature space. These bitmaps are used as the classifiers for real-time detection. The proposed method is extremely efficient in both the offline machine learning and real-time detection components. Results using the 1999 DARPA Intrusion Detection Evaluation Data Set yield a 100% detection of all applicable attacks, with extremely low false positive rate. The approach is also evaluated on real traffic captures.
Keywords
computer networks; cryptography; telecommunication security; 2D feature space; high-speed network intrusion prevention; hypercube hash function; lightweight stateless payload inspection; network-based attack; packet-level anomaly detection; Costs; Counting circuits; Hardware; High-speed networks; Histograms; Hypercubes; Inspection; Intrusion detection; Payloads; Telecommunication traffic; Anomaly Detection; Network Intrusion Detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, 2008. LCN 2008. 33rd IEEE Conference on
Conference_Location
Montreal, Que
Print_ISBN
978-1-4244-2412-2
Electronic_ISBN
978-1-4244-2413-9
Type
conf
DOI
10.1109/LCN.2008.4664303
Filename
4664303
Link To Document