Adaptive Anomaly Detection for Network Security

Kamini Nalavade, B. B. Meshram · International Journal of Computer and Internet Security · 2013

Intrusion detection is an integral part of computer security. It improves the security of information systems by allowing the review of patterns of access in order to discover abnormal activity of users and serving as a deterrent to users attempts to bypass system privilege or protection mechanisms. Anomaly detection systems, a subset of intrusion detection systems, model the normal system/network behavior which enables them to be extremely effective in finding and foiling both known as well as unknown or zero day attacks. Anomaly detection is an important problem that has been researched within diverse application domains and many anomaly detection techniques have been specifically developed in past years. This paper is an attempt to provide a structured and comprehensive overview of research on anomaly detection techniques. The different aspects and approaches for anomaly detection are described. We hope that this survey will provide a better understanding of the different directions in which anomaly detection research has been done.

Read the paper · More papers on PaperTik