DocumentCode :
3475060
Title :
Baseline Profile Stability for Network Anomaly Detection
Author :
Kim, Yoohwan ; Jo, Ju-Yeon ; Suh, Kyunghee Kim
Author_Institution :
Sch. of Comput. Sci., Nevada Las Vegas Univ., NV
fYear :
2006
fDate :
10-12 April 2006
Firstpage :
720
Lastpage :
725
Abstract :
Network attacks are commonplace in the Internet. One of the defense mechanisms against the network attacks is using a baseline profile established during normal operation to detect the traffic that deviates from the baseline profile. However, this approach works only if there is a stable base profile representing the legitimate network traffic. Although there has been some preliminary research, the details of profiling, such as the profile format, its size and the traffic stability by site or time, have not been widely available. In this study, we analyze actual traffic traces from two Internet traffic archives and verify the traffic stability by various aspects. The analysis shows that there are significant differences in the traffic patterns among different sites. In addition, there are some differences between different time of day or different days, even within a site, suggesting that different profiles are needed for different times. The result of this study can be used practically to anomaly-based IDS for determining the stability of the traffic for a particular site, and the number of required traffic profiles based on the traffic patterns
Keywords :
Internet; computer network management; security of data; telecommunication traffic; Internet traffic archive; Internet traffic pattern; Internet traffic profile format; Internet traffic trace; baseline profile stability; intrusion detection system; legitimate network traffic representation; network anomaly detection; network attack defense mechanism; network traffic stability; stable base profile; Computer crime; Computer science; IP networks; Information filtering; Information filters; Internet; Intrusion detection; Stability; TCPIP; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Technology: New Generations, 2006. ITNG 2006. Third International Conference on
Conference_Location :
Las Vegas, NV
Print_ISBN :
0-7695-2497-4
Type :
conf
DOI :
10.1109/ITNG.2006.38
Filename :
1611690
Link To Document :
بازگشت