Title :
A flow based anomaly detection system using chi-square technique
Author :
Muraleedharan, N. ; Parmar, Arun ; Kumar, Manish
Author_Institution :
Comput. Networking & Internet Eng., Centre for Dev. of Adv. Comput. (C-DAC), Bangalore, India
Abstract :
Various tools, which are capable to evade different security mechanisms like firewall, IDS and IPS, exist and that helps the intruders for sending malicious traffic to the network or system. So, inspection of malicious traffic and identification of anomalous activity is very much essential to stop future activity of intruders which can be a possible attack. In this paper we present a flow based system to detect anomalous activity by using IP flow characteristics with chi-square detection mechanism. This system provides solution to identify anomalous activities like scan and flood attack by means of automatic behavior analysis of the network traffic and also give detailed information of attacker, victim, type and time of the attack which can be used for corresponding defense. Anomaly Detection capability of the proposed system is compared with SNORT Intrusion detection system and results prove the very high detection rate of the system over SNORT for different scan and flood attack. The proposed system detects different stealth scan and malformed packets scan. Since the probability of using stealth scan in real attack is very high, this system can identify the real attacks in the initial stage itself and preventive action can be taken.
Keywords :
security of data; IDS; IPS; SNORT intrusion detection system; automatic behavior analysis; chi-square technique; firewall; flow based anomaly detection system; intrusion detection; malicious traffic; network traffic; security mechanisms; Computer networks; Floods; High-speed networks; IP networks; Information analysis; Inspection; Intrusion detection; Monitoring; Protocols; Telecommunication traffic; Anomaly detection; chi-square; flow; scan detection;
Conference_Titel :
Advance Computing Conference (IACC), 2010 IEEE 2nd International
Conference_Location :
Patiala
Print_ISBN :
978-1-4244-4790-9
Electronic_ISBN :
978-1-4244-4791-6
DOI :
10.1109/IADCC.2010.5422996