• DocumentCode
    3714150
  • Title

    Anomaly detection method using network pattern analysis of process

  • Author

    Minho Han;Ikkyun Kim

  • Author_Institution
    Cyber Security Research Laboratory Electronics & Telecommunications Research Institute Daejeon, Korea
  • fYear
    2015
  • Firstpage
    159
  • Lastpage
    163
  • Abstract
    The only solution against zero day attack is the anomaly based detection independent of specific signatures. The basic mechanism in the anomaly detection approach is establishing a profile to describe the “normal” situation of a network or machine. If this profile was accurate enough, all attacks should be detected because they are “abnormal” to the profile. Until now, there has no effective method to construct such a perfect profile. Also, the biggest problem is the dilemma between detection rate and false positive. Therefore, in this paper, we present a new solution to reduce false positive by network pattern analysis of process.
  • Keywords
    "Internet","Security"
  • Publisher
    ieee
  • Conference_Titel
    Internet Security (WorldCIS), 2015 World Congress on
  • Type

    conf

  • DOI
    10.1109/WorldCIS.2015.7359435
  • Filename
    7359435