Title :
Anomalous packet identification for network intrusion detection
Author :
Summervill, Douglas H. ; Nwanze, Nnamdi ; Skormin, Victor A.
Author_Institution :
Dept. of Electr. & Comput. Eng., Binghamton Univ., NY, USA
Abstract :
A packet-level anomaly detection system for network intrusion detection in high-bandwidth network environments is described. The approach is intended for hardware implementation and could be included in the network interface, switch or firewall. Efficient implementation in software on a network host is also possible. Network traffic is characterized using a novel technique that maps packet-level payloads onto a set of counters using bit-pattern hash functions, which were chosen for their implementation efficiency in both hardware and software. Machine learning is accomplished by mapping unlabelled training data onto a set of two-dimensional grids and forming a set of bitmaps that identify anomalous and normal regions. These bitmaps are used as the classifiers for real-time detection. The proposed method is extremely efficient in both the offline machine learning and real-time detection components and has the potential to provide accurate detection performance due to the ability of the bitmaps to capture nearly arbitrary shaped regions in the feature space. Results of a preliminary study are presented that demonstrate the effectiveness of the technique.
Keywords :
computer networks; learning (artificial intelligence); real-time systems; security of data; telecommunication security; anomaly detection system; anomaly packet identification; bit-pattern hash function; firewall; high-bandwidth network; machine learning; network interface; network intrusion detection; network traffic; Computer networks; Counting circuits; Filters; Hardware; Intrusion detection; Machine learning; Monitoring; Sensor phenomena and characterization; Switches; Telecommunication traffic;
Conference_Titel :
Information Assurance Workshop, 2004. Proceedings from the Fifth Annual IEEE SMC
Print_ISBN :
0-7803-8572-1
DOI :
10.1109/IAW.2004.1437798