An Approach to Model Normal Network Behaviors Based on Entire Network Packets

Zhao Tie-shan, Zengzhi Li, Wang Ze-ming, Lin Xiao-fen · 2008

Anomaly detection can detect unknown or new intrusions, and there are increasing interest in it. A normal network behavior model is necessary in any anomaly detection. Assuming that abnormal network behaviors are obviously different from normal ones, there should be some abnormal network packets that are obviously different from normal packets. Normal network packets are disassembled into binary strings whose lengths are l, and all the strings construct a set Unormal. The normal network behavior model is a set Umodel. The length of each element in Umodelis also l. Umodelis made up of those elements each of which matches at least one element in Unormaland doesn't match any other element in Umodel. Normal network behaviors hide in Umodel. The size of Umodelis discussed. Experimental results indicate that abnormal network behaviors can feasibly be detected with Umodel. Further work is to construct a more feasible Umodelto put into practice.

Read the paper · More papers on PaperTik