Application-layer Anomaly Detection Based on Application-layer Protocols' Keywords

被引:0
|
作者
Xie, Bailin [1 ]
Zhang, Qiansheng [1 ]
机构
[1] Guangdong Univ Foreign Studies, Cisco Sch Informat, Guangzhou, Guangdong, Peoples R China
关键词
application-layer; anomaly detection; protocols' keywords; hidden semi-Markov model;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays most network-based attacks are based on application-layer protocols and don't present significant difference in network traffic. Observed from the network-layer and transport-layer, these attacks may not contain significant malicious activities, and generate abnormal network traffic. So it is difficult for existing methods to effectively detect such application-layer attacks without special techniques. In theory, application-layer anomaly detection can detect the known, unknown and novel attacks happened on application-layer, therefore the research of application-layer anomaly detection is very important. This paper presents an application-layer anomaly detection method based on application-layer protocols' keywords. In this method, the keywords of an application-layer protocol and their inter-arrival times are used as the observations, a hidden semi-Markov model is used to describe the behaviors of a normal user who is using the application-layer protocol. The experimental results show that this method has high detection accuracy and low false positive ratio.
引用
收藏
页码:2131 / 2135
页数:5
相关论文
共 50 条
  • [41] Estimating AS relationships for application-layer traffic optimization
    University of Tokyo, Japan
    Lect. Notes Comput. Sci., (51-63):
  • [42] An application-layer multicasting protocol for distributed collaboration
    Shirmohammadi, S
    Diabi, A
    Lacombe, P
    2005 IEEE International Workshop on Haptic Audio Visual Environments and their Applications, 2005, : 139 - 142
  • [43] Application-layer based centralized information access control for VPN
    Ouyang K.
    Zhou J.-L.
    Xia T.
    Yu S.-S.
    J Zhejiang Univ: Sci, 2006, 2 (240-249): : 240 - 249
  • [44] AutoGuard: A Dual Intelligence Proactive Anomaly Detection at Application-Layer in 5G Networks
    Madi, Taous
    Alameddine, Hyame Assem
    Pourzandi, Makan
    Boukhtouta, Amine
    Shoukry, Moataz
    Assi, Chadi
    COMPUTER SECURITY - ESORICS 2021, PT I, 2021, 12972 : 715 - 735
  • [45] Estimating AS Relationships for Application-Layer Traffic Optimization
    Asai, Hirochika
    Esaki, Hiroshi
    INCENTIVES, OVERLAYS, AND ECONOMIC TRAFFIC CONTROL, 2010, 6236 : 51 - 63
  • [46] Selfishness-aware Application-Layer Multicast
    Wang Miao
    Peng Ge
    Zhang Yujun
    Li Guojie
    2010 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE GLOBECOM 2010, 2010,
  • [47] Heuristic algorithm for application-layer multicast structure
    Szabolcs, Kiss
    Piroska, Haller
    5TH ROEDUNET IEEE INTERNATIONAL CONFERENCE, PROCEEDINGS, 2006, : 199 - 203
  • [48] Improving Reliability for Application-Layer Multicast Overlays
    Tian, Ye
    Shen, Hong
    Ng, Kam-Wing
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2010, 21 (08) : 1103 - 1116
  • [49] Application-layer protocol for collaborative multimedia presentations
    Hwang, E
    Prabhakaran, B
    MULTIMEDIA TOOLS AND APPLICATIONS, 2003, 21 (02) : 103 - 123
  • [50] Application-Layer DDoS Defense with Reinforcement Learning
    Feng, Yebo
    Li, Jun
    Thanh Nguyen
    2020 IEEE/ACM 28TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2020,