Improving intrusion detection performance using keyword selection and neural networks

被引:117
作者
Lippmann, RP [1 ]
Cunningham, RK [1 ]
机构
[1] MIT, Lincoln Lab, Lexington, MA 02420 USA
来源
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING | 2000年 / 34卷 / 04期
关键词
intrusion detection; neural net; keyword; network; attack;
D O I
10.1016/S1389-1286(00)00140-7
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The most common computer intrusion detection systems detect signatures of known attacks by searching for attack-specific keywords in network traffic. Many of these systems suffer from high false-alarm rates (often hundreds of false alarms per day) and poor detection of new attacks. Poor performance can be improved using a combination of discriminative training and generic keywords. Generic keywords are selected to detect attack preparations, the actual break-in, and actions after the break-in. Discriminative training weights keyword counts to discriminate between the few attack sessions where keywords are known to occur and the many normal sessions where keywords may occur in other contexts. This approach was used to improve the baseline keyword intrusion detection system used to detect user-to-root attacks in the 1998 DARPA Intrusion Detection Evaluation. It reduced the false-alarm rate required to obtain 80% correct detections by two orders of magnitude to roughly one false alarm per day. The improved keyword system detects new as well as old attacks in this database and has roughly the same computation requirements as the original baseline system. Both generic keywords and discriminant training were required to obtain this large performance improvement. (C) 2000 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:597 / 603
页数:7
相关论文
共 13 条
  • [1] ALLEN J, 2000, CMUSEI99TR028 CARN U
  • [2] AMOROSO EG, 1999, INTRUSTION DETECTION
  • [3] *CISC SYST INC, 1998, NETR INTR DET SYST T
  • [4] Heberlein T, 1995, NETWORK SECURITY MON
  • [5] *L LIV NAT LAB, 1998, NETW INTR DET NID OV
  • [6] Lee W., 1999, P 5 ACM SIGKDD INT C, P114, DOI 10.1145/312129.312212
  • [7] The 1999 DARPA off-line intrusion detection evaluation
    Lippmann, R
    Haines, JW
    Fried, DJ
    Korba, J
    Das, K
    [J]. COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2000, 34 (04): : 579 - 595
  • [8] Lippmann R. P., 1993, Lincoln Laboratory Journal, V6, P249
  • [9] Lippmann R. P., 2000, P 2000 DARPA INF SUR, V2
  • [10] LIPPMANN RP, 1999, IDDE1 MIT LINC LAB