Anomaly detection methods in wired networks: a survey and taxonomy

被引:129
作者
Estevez-Tapiador, JM [1 ]
Garcia-Teodoro, P [1 ]
Diaz-Verdejo, JE [1 ]
机构
[1] Univ Granada, Dept Elect & Comp Technol, Res Grp Signals Telemat & Commun, ETS Ingn Informat, E-18071 Granada, Spain
关键词
anomaly detection; network intrusion detection; computer and network security; network management;
D O I
10.1016/S0140-3664(04)00238-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 [计算机科学与技术];
摘要
Despite the advances reached along the last 20 years, anomaly detection in network behavior is still an immature technology, and the shortage of commercial tools thus corroborates it. Nevertheless, the benefits which could be obtained from a better understanding of the problem itself as well as the improvement of these mechanisms, especially in network security, justify the demand for more research efforts in this direction. This article presents a survey on current anomaly detection methods for network intrusion detection in classical wired environments. After introducing the problem and elucidating its interest, a taxonomy of current solutions is presented. The outlined scheme allows us to systematically classify current detection methods as well as to study the different facets of the problem. The more relevant paradigms are subsequently discussed and illustrated through several case studies of selected systems developed in the field. The problems addressed by each of them as well as their weakest points are thus explained. Finally, this work concludes with an analysis of the problems that still remain open. Based on this discussion, some research lines are identified. (C) 2004 Elsevier B.V. All rights reserved.
引用
收藏
页码:1569 / 1584
页数:16
相关论文
共 42 条
[1]
Allen J, 2000, CMUSEI99TR028
[2]
Anderson D., 1994, NEXT GENERATION INTR
[3]
Anderson J.P., 1980, Computer security threat monitoring and surveillance
[4]
[Anonymous], 2000, CIAC2319
[5]
Athanasiades N, 2003, IWIA 2003: FIRST IEEE INTERNATIONAL WORKSHOP ON INFORMATION ASSURANCE, PROCEEDINGS, P63
[6]
BARFORD P, 2002, P ACM SIGCOMM INT ME
[7]
Barford P., 2001, P ACM SIGCOMM INT ME
[8]
Bellovin S. M., 1993, Computer Communication Review, V23, P26, DOI 10.1145/174194.174199
[9]
Detecting network intrusions via a statistical analysis of network packet characteristics [J].
Bykova, M ;
Ostermann, S ;
Tjaden, B .
PROCEEDINGS OF THE 33RD SOUTHEASTERN SYMPOSIUM ON SYSTEM THEORY, 2001, :309-314
[10]
Statistical traffic modeling for network intrusion detection [J].
Cabrera, JBD ;
Ravichandran, B ;
Mehra, RK .
8TH INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS AND SIMULATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS, PROCEEDINGS, 2000, :466-473