MCAD: Multiple connection based anomaly detection

Xin He, Sri Parameswaran · 2008

This paper describes a novel multi-connection based anomaly detection system. Previous techniques consume enormous amounts of time due to pre-processing features (unsupervised anomaly detection), or due to the lead time in creating specialized rules (supervised anomaly detection). The system described in this paper, MCAD, uses the observed premise that anomalous connections by one attacker are very similar to each other (e.g. an attacker will try to use similar connections to probe a network). MCAD tests for similarity amongst connections within clustered groups, and if the similarity for connections of the group is above a predetermined threshold, then these connections are deemed anomalous. MCAD was tested on two weeks of MIT/LL DARPA dataset. The total number connections tested was over a million. From this testing, MCAD was able to detect 15 types of multiple connection based attacks in which 14 types of attacks were fully detected while the 15th attack was detected 2/3 of the time. The false positive rate was 0.466%.

Read the paper · More papers on PaperTik