DocumentCode :
679605
Title :
Constant false alarm rate anomaly-based approach for network intrusion detection
Author :
AlShaalan, Rayan ; AsSadhan, Basil ; Al-Muhtadi, Jalal ; Bin-Abbas, Hesham ; El-Samie, Fathi Abd ; Alshebeili, Saleh
Author_Institution :
Deptartment of Electr. Eng., King Saud Univ., Riyadh, Saudi Arabia
fYear :
2013
fDate :
11-13 Dec. 2013
Firstpage :
141
Lastpage :
145
Abstract :
With the rapid growth of communication technologies, the widespread use of the Internet, and the recent introduction of e-services, the number of computer network security threats is dramatically increasing. This paper presents an efficient method for anomaly detection in network traffic. In this method, network traffic is decomposed into control and data planes. As the data traffic generation is based on control traffic, the behavior of the two planes is expected to be similar during normal behavior. Therefore, detecting dissimilarity (via cross-correlation) between the traffic of the two planes can indicate an abnormal behavior. Constant and adaptive thresholding techniques have been developed in this paper for the design of a false alarm rate intrusion detection processors. Simulation experiments have been carried out on a real traffic obtained at King Saud University at the end of 2012.
Keywords :
computer network security; telecommunication traffic; Internet; adaptive thresholding technique; anomaly detection; communication technology; computer network security threats; constant false alarm rate anomaly; constant thresholding technique; control traffic; data traffic generation; e-services; false alarm rate intrusion detection processor; network intrusion detection; network traffic; Computer crime; Correlation; Floods; Intrusion detection; Ports (Computers); Telecommunication traffic; CFAR; Network traffic analysis; TCP SYN flooding; anomaly detection; intrusion detection systems; port scanning;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
High Capacity Optical Networks and Enabling Technologies (HONET-CNS), 2013 10th International Conference on
Conference_Location :
Magosa
Print_ISBN :
978-1-4799-2568-1
Type :
conf
DOI :
10.1109/HONET.2013.6729773
Filename :
6729773
Link To Document :
بازگشت