Solving inherent problems of anomaly detection by cooperation
Data(s) |
2009
|
---|---|
Resumo |
Anomaly detection compensates shortcomings of signature-based detection such as protecting against Zero-Day exploits. However, Anomaly Detection can be resource-intensive and is plagued by a high false-positive rate. In this work, we address these problems by presenting a Cooperative Intrusion Detection approach for the AIS, the Artificial Immune System, as an example for an anomaly detection approach. In particular we show, how the cooperative approach reduces the false-positive rate of the detection and how the overall detection process can be organized to account for the resource constraints of the participating devices. Evaluations are carried out with the novel network simulation environment NeSSi as well as formally with an extension to the epidemic spread model SIR |
Identificador | |
Publicador |
DAI Labor |
Relação |
http://www.dai-labor.de/fileadmin/files/publications/TRCoop0209-01.pdf Bye, Rainer, Luther, Katja, Camtepe, Seyit A., & Albayrak, Sahin (2009) Solving inherent problems of anomaly detection by cooperation. DAI Labor, Berlin. |
Fonte |
School of Electrical Engineering & Computer Science; Information Security Institute; Science & Engineering Faculty |
Palavras-Chave | #080303 Computer System Security #intrusion detection #anomaly detection #collaboration |
Tipo |
Report |