Detecting intrusion with rule-based integration of multiple models

被引:34
|
作者
Han, SJ [1 ]
Cho, SB [1 ]
机构
[1] Yonsei Univ, Dept Comp Sci, Seoul 120749, South Korea
关键词
intrusion detection systems; anomaly detection; multi-measure modeling;
D O I
10.1016/S0167-4048(03)00711-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the information technology grows interests in the intrusion detection system (IDS), which detects unauthorized usage, misuse by a local user and modification of important data, has been raised. In the field of anomaly,based IDS several data mining techniques such as hidden Markov model (HMM), artificial neural network, statistical techniques and expert systems are used to model network packets, system call audit data, etc. However, there are undetectable intrusion types for each measure and modeling method because each intrusion type makes anomalies at individual measure. To overcome this drawback of single-measure anomaly detector, this paper proposes a multiple-measure intrusion detection method. We measure normal behavior by systems calls, resource usage and file access events and build up profiles for normal behavior with hidden Markov model, statistical method and rule-base method, which are integrated with a rule based approach. Experimental results with real data clearly demonstrate the effectiveness of the proposed method that has significantly low false,positive error rate against various type's of intrusion.
引用
收藏
页码:613 / 623
页数:11
相关论文
共 50 条
  • [1] Rule-based integration of multiple measure-models for effective intrusion detection
    Han, SJ
    Cho, SB
    [J]. 2003 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS, VOLS 1-5, CONFERENCE PROCEEDINGS, 2003, : 120 - 125
  • [2] Annotation of SBML models through rule-based semantic integration
    Lister A.L.
    Lord P.
    Pocock M.
    Wipat A.
    [J]. Journal of Biomedical Semantics, 1 (Suppl 1)
  • [3] Rule-based COTS integration
    Boonsiri, S
    Seacord, RC
    Mundie, DA
    [J]. JOURNAL OF RESEARCH AND PRACTICE IN INFORMATION TECHNOLOGY, 2003, 35 (03): : 197 - 204
  • [4] Inmplode: A framework to interpret multiple related rule-based models
    Strecht, Pedro
    Mendes-Moreira, Joao
    Soares, Carlos
    [J]. EXPERT SYSTEMS, 2021, 38 (06)
  • [5] Rule-based epidemic models
    Waites, W.
    Cavaliere, M.
    Manheim, D.
    Panovska-Griffiths, J.
    Danos, V.
    [J]. JOURNAL OF THEORETICAL BIOLOGY, 2021, 530
  • [6] Containment in Rule-Based Models
    Thompson-Walsh, C. D.
    Hayman, J.
    Winskel, G.
    [J]. ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2012, 284 : 125 - 137
  • [7] Integration of rule-based systems and database
    Kaula, R
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2000, 40 (03) : 38 - 43
  • [8] Building agents for rule-based intrusion detection system
    Jha, S
    Hassan, M
    [J]. COMPUTER COMMUNICATIONS, 2002, 25 (15) : 1366 - 1373
  • [9] Integration of Ohman and Rule-based Coarticulation Models for Visualization of Pure Lithuanian Diphtongs
    Mazonaviciute, I.
    Bausys, R.
    Kriukovas, A.
    [J]. ELEKTRONIKA IR ELEKTROTECHNIKA, 2013, 19 (01) : 69 - 72
  • [10] Formal Reduction for Rule-based Models
    Camporesi, Ferdinanda
    Feret, Jerome
    [J]. ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2011, 276 : 29 - 59