Incremental Approaches for Network Anomaly Detection: Existing Solutions and Challenges
Monowar H. Bhuyan, Dhruba K. Bhattacharyya, Jugal Kumar Kalita · 2011
As the communication industry has connected distant corners of the globe using advances in netw ork technology, intruders or attackers have also increa sed attacks on networking infrastructure commensurately. System administrators can attempt to prevent such attacks using intrusion detection tools and systems. There are ma ny commercially available signature-based Intrusion De tection Systems (IDSs). However, most IDSs lack the capability to detect novel or previously unknown attacks. A speci al type of IDSs, called Anomaly Detection Systems, develop models based on normal system or network behavior, with the goal of detecting both known and unknown attacks. Anomaly detection systems face many problems including high rate of f alse alarm, ability to work in online mode, and scalability. Th is paper presents a selective survey of incremental approach es for detecting anomaly in normal system or network traffic. The technological trends, open problems, and challenges over anomaly detection using incremental approach are al so discussed.