• DocumentCode
    3712631
  • Title

    Insider attack detection using weak indicators over network flow data

  • Author

    Roberto Pagliari;Abhrajit Ghosh;Yitzchak M. Gottlieb;Ritu Chadha;Akshay Vashist;Gregory Hadynski

  • Author_Institution
    Applied Communication Sciences, Basking Ridge, NJ, U.S.A.
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Insider attack detection in an enterprise network environment is a critical problem that currently has no promising solution. It represents a significant challenge since host availability and performance requirements cannot be ignored. A network based approach allows these requirements to be met but is limited by the granularity of data available and the near impossibility of defining exact signatures for known attack types. Anomaly detection approaches suffer from the well known problem of false positives making them hard to apply in enterprise environments where even a moderate false positive rate is not acceptable. Sophisticated attacks and complex network topologies make it hard to apply simplistic approaches to anomaly detection. This paper presents an approach that applies the unsupervised learning techniques of bi-clustering and one-class SVM to so-called weak indicators of network attacks. This approach is well suited for network flow data that is coarse grained and not amenable to simplistic anomaly detection or signature-based techniques. Further, our approach allows a security analyst to determine the cause of the anomaly, a capability that is typically not supportable by simplistic applications of unsupervised learning.
  • Keywords
    "Feature extraction","Ports (Computers)","Databases","Servers","Data mining","Couplings","IP networks"
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, MILCOM 2015 - 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/MILCOM.2015.7357409
  • Filename
    7357409