Intrusion Detection in Multiservice Network on the Basis of Registered Traffic Filtration
Vyacheslav Kartashevskiy, Irina Pozdnyak, Marina Buranova · 2018
The paper proposes a detection option of the anomalous component of the observed traffic based on traffic processing by a linear filter with a known impulse response. Based on a comparison of the current value of the mean-square filter error with the "reference" value obtained by filtering traffic without anomalies, it is possible to detect attacks that change the statistical properties of the traffic. When filtering traffic without anomalies, the mean square filter error is determined by the cross correlation function of the observed traffic without intrusions and traffic at the output of the linear filter. The impulse response of such traffic is determined by the correlation properties of the "reference" traffic. The presence of an intrusion into the observed traffic changes its correlation properties. This leads to a noticeable increase in the mean-square filter error. Comparison of the obtained value of the mean-square error with the "reference" value allows to draw conclusions about the presence of an anomalous component.