A new statistical method for detecting network anomalies in TCP traffic

被引:13
作者
Callegari, Christian [1 ]
Vaton, Sandrine [2 ]
Pagano, Michele [3 ,4 ,5 ]
机构
[1] Univ Pisa, Dept Informat Engn, Telecommun Network Res Grp, Pisa, Italy
[2] TELECOM Bretagne, Dept Comp Sci, Brest, France
[3] Univ Pisa, Dept Informat Engn, Course Telemat, Pisa, Italy
[4] Univ Pisa, Dept Informat Engn, Course Performance Multimedia Networks, Pisa, Italy
[5] Univ Pisa, Dept Informat Engn, Course Network Secur, Pisa, Italy
来源
EUROPEAN TRANSACTIONS ON TELECOMMUNICATIONS | 2010年 / 21卷 / 07期
关键词
INTRUSION DETECTION; MODEL;
D O I
10.1002/ett.1432
中图分类号
TN [电子技术、通信技术];
学科分类号
080906 [电磁信息功能材料与结构];
摘要
In the last few years, the number and impact of security attacks over the Internet have been continuously increasing. To face this issue, the use of Intrusion Detection Systems (IDSs) has emerged as a key element in network security. In this paper we address the problem considering a novel statistical technique for detecting network anomalies. Our approach is based on the use of different families of Markovian models. namely high order and non-homogeneous Markov chains, for modeling network traffic running over TCP. The performance results shown in the paper justify the proposed method and highlight the improvements over commonly used statistical techniques. Copyright (C) 2010 John Wiley & Sons, Ltd.
引用
收藏
页码:575 / 588
页数:14
相关论文
共 17 条
[1]
*CERT, CERT RES ANN REP
[2]
Denning D.E., 1987, SOFTWARE ENG IEEE T, VSE-13, P222
[3]
HAINES JW, 2001, 1999 DAPRA INTRUSION
[4]
A NEW SMOOTHING-REGULARIZATION APPROACH FOR A MAXIMUM-LIKELIHOOD-ESTIMATION PROBLEM [J].
IUSEM, AN ;
SVAITER, BF .
APPLIED MATHEMATICS AND OPTIMIZATION, 1994, 29 (03) :225-241
[5]
JU WH, 1999, 92 NISS
[6]
KEMMERER RA, 2002, IEEE COMPUT, V35, P27
[7]
The 1999 DARPA off-line intrusion detection evaluation [J].
Lippmann, R ;
Haines, JW ;
Fried, DJ ;
Korba, J ;
Das, K .
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2000, 34 (04) :579-595
[8]
*MIT LINC LAB, DARPA EV INTR DET
[9]
Mood A. M., 1974, Introduction to the Theory of Statistics, V3rd ed.
[10]
RAFTERY A, 1994, J R STAT SOC C-APPL, V43, P179