Hurst Parameter Based Anomaly Detection for Intrusion Detection System
Song Jin Yu, Pauline Koh, Hyukmin Kwon, Dong Seong Kim, Huy Kang Kim · 2016
Cyber-attack technologies have been evolved continuously. As a result, new attacks and their variants appearevery day. Also, intelligent and malicious attackers use varioustechniques to bypass the current signature and anomalydetection based intrusion detection systems. To detect thenew attacks more effectively, new anomaly detection modelis needed. In this paper, we propose a novel anomaly detectionmethod based on the self-similarity estimation of systems andnetworks. We primarily use the self-similarity property whichis characterized by the Hurst parameter. With the proposedmethod, we can detect network and system's anomaly statusby computing the change of self-similarity value. We evaluatedthe effectiveness and efficiency of our approach using the'1999 DARPA Intrusion Detection Evaluation dataset'. Also, we deployed the self-similarity based IDS in the real watergrid system.