Solving inherent problems of anomaly detection by cooperation


Autoria(s): Bye, Rainer; Luther, Katja; Camtepe, Seyit A.; Albayrak, Sahin
Data(s)

2009

Resumo

Anomaly detection compensates shortcomings of signature-based detection such as protecting against Zero-Day exploits. However, Anomaly Detection can be resource-intensive and is plagued by a high false-positive rate. In this work, we address these problems by presenting a Cooperative Intrusion Detection approach for the AIS, the Artificial Immune System, as an example for an anomaly detection approach. In particular we show, how the cooperative approach reduces the false-positive rate of the detection and how the overall detection process can be organized to account for the resource constraints of the participating devices. Evaluations are carried out with the novel network simulation environment NeSSi as well as formally with an extension to the epidemic spread model SIR

Identificador

http://eprints.qut.edu.au/58484/

Publicador

DAI Labor

Relação

http://www.dai-labor.de/fileadmin/files/publications/TRCoop0209-01.pdf

Bye, Rainer, Luther, Katja, Camtepe, Seyit A., & Albayrak, Sahin (2009) Solving inherent problems of anomaly detection by cooperation. DAI Labor, Berlin.

Fonte

School of Electrical Engineering & Computer Science; Information Security Institute; Science & Engineering Faculty

Palavras-Chave #080303 Computer System Security #intrusion detection #anomaly detection #collaboration
Tipo

Report