A new statistical method for detecting network anomalies in TCP traffic

Christian Callegari, Sandrine Vaton, Michele Pagano · European Transactions on Telecommunications · 2010

Abstract In the last few years, the number and impact of security attacks over the Internet have been continuously increasing. To face this issue, the use of Intrusion Detection Systems (IDSs) has emerged as a key element in network security. In this paper we address the problem considering a novel statistical technique for detecting network anomalies. Our approach is based on the use of different families of Markovian models, namely high order and non‐homogeneous Markov chains, for modeling network traffic running over TCP. The performance results shown in the paper justify the proposed method and highlight the improvements over commonly used statistical techniques. Copyright © 2010 John Wiley & Sons, Ltd.

Read the paper · More papers on PaperTik