Towards data mining temporal patterns for anomaly intrusion detection systems

Sam Sengupta, Bruno Andriamanalimanana, Stuart W. Card, Priya U. Kadam, Saket Ranwadkar, Kaustav Das, Shilpa Parikh · 2004

A reasonably light-weight host and net-centric network IDS architecture model is indicated. The model is anomaly based on a state-driven notion of "anomaly". Therefore, the relevant distribution function need not remain constant; it could migrate from states to states without any a priori warning so long as its residency time at a next steady state is sufficiently long to make valid observations there. Only those intrusion events (basically DOS and DDOS variety) capable of triggering anomalous streams of attacks/response both near and/or far of target monitoring point(s) are considered at the first level of detection. At the next level of detection, the filtered states could be fine-combed in a batch mode to mine unacceptable strings of commands or known attack signatures

Read the paper · More papers on PaperTik