HMMPayl: An intrusion detection system based on Hidden Markov Models

被引:76
|
作者
Ariu, Davide [1 ]
Tronci, Roberto [1 ]
Giacinto, Giorgio [1 ]
机构
[1] Univ Cagliari Piazza Armi, Dept Elect & Elect Engn, I-09123 Cagliari, Italy
关键词
Network intrusion detection; Anomaly detection; Multiple classifiers; Hidden Markov Models; Payload analysis; PROBABILISTIC FUNCTIONS; FUSION;
D O I
10.1016/j.cose.2010.12.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays the security of Web applications is one of the key topics in Computer Security. Among all the solutions that have been proposed so far, the analysis of the HTTP payload at the byte level has proven to be effective as it does not require the detailed knowledge of the applications running on the Web server. The solutions proposed in the literature actually achieved good results for the detection rate, while there is still room for reducing the false positive rate. To this end, in this paper we propose HMMPayl, an IDS where the payload is represented as a sequence of bytes, and the analysis is performed using Hidden Markov Models (HMM). The algorithm we propose for feature extraction and the joint use of HMM guarantee the same expressive power of n - gram analysis, while allowing to overcome its computational complexity. In addition, we designed HMMPayl following the Multiple Classifiers System paradigm to provide for a better classification accuracy, to increase the difficulty of evading the IDS, and to mitigate the weaknesses due to a non optimal choice of HMM parameters. Experimental results, obtained both on public and private datasets, show that the analysis performed by HMMPayl is particularly effective against the most frequent attacks toward Web applications (such as XSS and SQL-Injection). In particular, for a fixed false positive rate, HMMPayl achieves a higher detection rate respect to previously proposed approaches it has been compared with. (C) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:221 / 241
页数:21
相关论文
共 50 条
  • [1] An Intrusion Detection Method Based on Hierarchical Hidden Markov Models
    JIA Chunfu1
    2. College of Information Technology and Science
    [J]. Wuhan University Journal of Natural Sciences, 2007, (01) : 135 - 138
  • [2] HMMs (Hidden Markov models) based on anomaly intrusion detection method
    Gao, B
    Ma, HY
    Yang, YH
    [J]. 2002 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-4, PROCEEDINGS, 2002, : 381 - 385
  • [3] Intrusion detection based on Hidden Markov Model
    Yin, QB
    Shen, LR
    Zhang, RB
    Li, XY
    Wang, HQ
    [J]. 2003 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-5, PROCEEDINGS, 2003, : 3115 - 3118
  • [4] Hidden Markov model based intrusion detection
    Liu, Zhi-Yong
    Qiao, Hong
    [J]. INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2006, 3917 : 169 - 170
  • [5] Research of IOT Intrusion Detection System Based on Hidden Markov Model
    Jiang, Xuesong
    Wei, Xiumei
    Wang, Xingang
    [J]. 2011 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND APPLICATIONS, 2011, : 151 - 155
  • [6] Research of IOT Intrusion Detection System Based on Hidden Markov Model
    Wei, Xiumei
    Jiang, Xuesong
    Wang, Xingang
    [J]. INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY, PTS 1-4, 2013, 263-266 : 2949 - 2952
  • [7] Modeling program behaviors by hidden Markov models for intrusion detection
    Wang, W
    Guan, XH
    Zhang, XL
    [J]. PROCEEDINGS OF THE 2004 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2004, : 2830 - 2835
  • [8] Hidden Markov Model Based Anomaly Intrusion Detection
    Jain, Ruchi
    Abouzakhar, Nasser S.
    [J]. 2012 INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS, 2012, : 528 - 533
  • [9] Mobile agent based intrusion detection system adopting Hidden Markov Model
    Lee, Do-hyeon
    Kim, Doo-young
    Jung, Jae-il
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2007, PT 2, PROCEEDINGS, 2007, 4706 : 122 - 130
  • [10] Multi-Layer Hidden Markov Model Based Intrusion Detection System
    Zegeye, Wondimu K.
    Dean, Richard A.
    Moazzami, Farzad
    [J]. MACHINE LEARNING AND KNOWLEDGE EXTRACTION, 2019, 1 (01): : 265 - 286