DocumentCode :
3549433
Title :
The effects of algorithmic diversity on anomaly detector performance
Author :
Tan, Kymie M C ; Maxion, Roy A.
Author_Institution :
Dept. of Comput. Sci., Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear :
2005
fDate :
28 June-1 July 2005
Firstpage :
216
Lastpage :
225
Abstract :
Common practice in anomaly-based intrusion detection assumes that one size fits all: a single anomaly detector should detect all anomalies. Compensation for any performance shortcoming is sometimes effected by resorting to correlation techniques, which could be seen as making use of detector diversity. Such diversity is intuitively based on the assumption that detector coverage is different - perhaps widely different - for different detectors, each covering some disparate portion of the anomaly space. Diversity, then, enhances detection coverage by combining the coverages of individual detectors across multiple sub-regions of the anomaly space, resulting in an overall detection coverage that is superior to the coverage of any one detector. No studies have been done, however, in which measured effects of diversity amongst anomaly detectors have been obtained. This paper explores the effects of using diverse anomaly-detection algorithms in intrusion detection. Experimental results indicate that while performance/coverage improvements can in fact be effected by combining diverse detection algorithms, the gains are not the result of combining large, non-overlapping regions of the anomaly space. Rather, the gains are seen at the edges of the space, and are heavily dependent on the parameter values of the detectors, as well as on anomaly characteristics. Based on this study, defenders can be provided with knowledge of how combinations of diverse, sequence-based detectors behave to effect detection performance superior to that of a single detector.
Keywords :
fault tolerant computing; performance evaluation; security of data; anomaly detector performance; anomaly-detection algorithm; intrusion detection; sequence-based detector; Computer science; Detection algorithms; Detectors; Diversity reception; Intrusion detection; Laboratories; Performance gain; Protocols; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks, 2005. DSN 2005. Proceedings. International Conference on
Print_ISBN :
0-7695-2282-3
Type :
conf
DOI :
10.1109/DSN.2005.91
Filename :
1467796
Link To Document :
بازگشت