DocumentCode :
2311287
Title :
Noise-Resistant Payload Anomaly Detection for Network Intrusion Detection Systems
Author :
Kim, Sun-il ; Nwanze, Nnamdi
Author_Institution :
Dept. of Comput. Sci., Univ. of Alabama in Huntsville, Huntsville, AL
fYear :
2008
fDate :
7-9 Dec. 2008
Firstpage :
517
Lastpage :
523
Abstract :
Anomaly-based intrusion detection systems are an essential part of a global security solution and effectively complement signature-based detection schemes. Its strength in detecting previously unknown and never seen attacks make it attractive, but it is more prone to higher false positives. In this paper, we present a simple payload based intrusion detection scheme that is resilient to contaminated traffic that may unintentionally be used during training. Our results show that, by adjusting the two tuning parameters used in our approach, the ability to detect attacks while maintaining low false positives is not hindered, even when 10% of the training traffic consists of attacks. Test results also show that our approach is not sensitive to changes in the parameters, and a wide range of values can be used to yield high per-packet detection rates (over 99.5%) while keeping false positives low (below 0.3%).
Keywords :
security of data; telecommunication security; contaminated traffic; global security solution; high per packet detection rates; network intrusion detection systems; noise resistant payload anomaly detection; signature based detection schemes; tuning parameters; Computer science; Computer security; Computer vision; Databases; Information security; Information technology; Intrusion detection; Payloads; Protection; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance, Computing and Communications Conference, 2008. IPCCC 2008. IEEE International
Conference_Location :
Austin, Texas
ISSN :
1097-2641
Print_ISBN :
978-1-4244-3368-1
Electronic_ISBN :
1097-2641
Type :
conf
DOI :
10.1109/PCCC.2008.4745080
Filename :
4745080
Link To Document :
بازگشت