Locality-based profile analysis for secondary intrusion detection

被引:0
|
作者
Zhou, M [1 ]
Lee, R [1 ]
Lang, SD [1 ]
机构
[1] Univ Cent Florida, Sch Elect Engn & Comp Sci, Orlando, FL 32816 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
While a firewall at the perimeter of a local network provides the first line of defense against attackers, many intrusion incidents result from successftd penetration of the firewall. The compromise of one computer puts the entire network at risk. We propose a distributed personal Intrusion Detection System (IDS) that provides local anomaly detection as well as centralized traffic analysis. The system first builds profiles for normal network activity and then labels as suspicious any events that deviate from the normal profiles. The normal profiles are based on variations in connection-based behavior at each individual host. Deviations at each host are recorded using a local weight assignment scheme and then further processed by the central analyzer to build a weighted link graph representing the overall network abnormality. As local networks become more vulnerable to inside attack, our system reinforces security to prevent corruption from the inside.
引用
收藏
页码:166 / 171
页数:6
相关论文
共 50 条
  • [31] Locality-based Peer Clustering for Efficient Overlay Networks
    Shin, Junghoon
    Joo, Sangwook
    Hwang, Kyu-Baek
    Lee, Sangjun
    Park, Jisook
    INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2010, 13 (03): : 657 - 665
  • [32] A locality-based LFH cluster strategy for overlay network
    Chen, Xing
    Yang, Qing
    2008 THE INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, 2008, : 325 - 329
  • [33] DISGUISED DISCRIMINATION OF LOCALITY-BASED UNSUPERVISED DIMENSIONALITY REDUCTION
    Yang, Bo
    Chen, Songcan
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2010, 24 (07) : 1011 - 1025
  • [34] Locality-based Multiobjectivization for the HP Model of Protein Structure Prediction
    Garza-Fabre, Mario
    Toscano-Pulido, Gregorio
    Rodriguez-Tello, Eduardo
    PROCEEDINGS OF THE FOURTEENTH INTERNATIONAL CONFERENCE ON GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE, 2012, : 473 - 480
  • [35] LOCALITY-BASED CONTROL ALGORITHMS FOR RECONFIGURABLE OPTICAL INTERCONNECTION NETWORKS
    CHIARULLI, DM
    LEVITAN, SP
    MELHEM, RG
    QIAO, CM
    APPLIED OPTICS, 1994, 33 (08): : 1528 - 1537
  • [36] Treatment of Syntactic Variation using a Locality-based Recovery Model
    Vilares, Jesus
    Alonso, Miguel A.
    PROCESAMIENTO DEL LENGUAJE NATURAL, 2006, (36): : 39 - 46
  • [37] A locality-based listing of African Plio-Pleistocene mammals
    Turner, A
    Bishop, LC
    Denys, C
    McKee, JK
    AFRICAN BIOGEOGRAPHY, CLIMATE CHANGE & HUMAN EVOLUTION, 1999, : 369 - 399
  • [38] Disputing the global: a sceptical view of locality-based international initiatives
    Beauregard, RA
    Pierre, J
    POLICY AND POLITICS, 2000, 28 (04): : 465 - 478
  • [39] Loco-Store: Locality-Based Oblivious Data Storage
    Tian, Wenlong
    Li, Ruixuan
    Xu, Zhiyong
    Xiao, Weijun
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (02) : 1395 - 1406
  • [40] A new locality-based IP multicasting scheme for mobile hosts
    Tseng, CC
    Chi, KH
    Huang, TL
    COMPUTER COMMUNICATIONS, 2001, 24 (5-6) : 486 - 495