DocumentCode
3255087
Title
A two-stage aggregation/thresholding scheme for multi-model anomaly-based approaches
Author
Tabia, Karim ; Benferhat, Salem ; Djouadi, Yassine
Author_Institution
Artois Univ.
fYear
2008
fDate
14-17 Oct. 2008
Firstpage
919
Lastpage
926
Abstract
This paper deals with anomaly score aggregation and thresholding in multi-model anomaly-based approaches which require multiple detection models and profiles in order to characterize the different aspects of normal activities. Most works focus on profile/model definition while critical issues related to anomaly measuring, aggregating and thresholding have not received similar attention. In this paper, we in particular address the issue of anomaly scoring and aggregating which is a recurring problem in multi-model anomaly-based approaches. We propose a two stage aggregation/thresholding scheme particularly suitable for multi-model anomaly-based approaches. The basic idea of our scheme is the fact that anomalous behaviors induce either intramodel anomalies or inter-model ones. Our scheme is designed for real-time detection of both intra-model and inter-model anomalies. More precisely, we propose local thresholding in order to detect intra-model anomalies and use a Bayesian network in order to, on one hand, extract inter-model regularities and serve, on the other hand, as an aggregating function for computing the overall anomaly score associated with each analyzed audit event. Our experimental studies, carried out on recent and real http traffic, show for instance that most Web-based attacks induce only intra-model anomalies and can be effectively detected in real-time. Moreover, this scheme significantly improves the detection rate of Web-based attacks involving inter-model anomalies.
Keywords
Web sites; security of data; aggregating function; anomaly score aggregation; multi-model anomaly-based approaches; two-stage aggregation/thresholding scheme; Bayesian methods; Computer networks; Computer science; Event detection; Information analysis; Information systems; Intrusion detection; Real time systems; Telecommunication traffic;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, 2008. LCN 2008. 33rd IEEE Conference on
Conference_Location
Montreal, Que
Print_ISBN
978-1-4244-2412-2
Electronic_ISBN
978-1-4244-2413-9
Type
conf
DOI
10.1109/LCN.2008.4664304
Filename
4664304
Link To Document