McPAD: A multiple classifier system for accurate payload-based anomaly detection

被引:138
|
作者
Perdisci, Roberto [1 ,2 ]
Ariu, Davide [3 ]
Fogla, Prahlad [4 ]
Giacinto, Giorgio [3 ]
Lee, Wenke [2 ]
机构
[1] Damballa Inc, Atlanta, GA 30308 USA
[2] Georgia Inst Technol, Coll Comp, Atlanta, GA 30308 USA
[3] Univ Cagliari, Dept Elect & Elect Engn, I-09123 Cagliari, Italy
[4] Google Inc, Mountain View, CA 94043 USA
关键词
Network intrusion detection; Anomaly detection; Shell-code attacks; Multiple classifiers; One-class SVM; INTRUSION DETECTION; ENSEMBLE; SUPPORT;
D O I
10.1016/j.comnet.2008.11.011
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly-based network intrusion detection systems (IDS) are valuable tools for the defense-in-depth of computer networks. Unsupervised or unlabeled learning approaches for network anomaly detection have been recently proposed. Such anomaly-based network IDS are able to detect (unknown) zero-day attacks, although much care has to be dedicated to controlling the amount of false positives generated by the detection system. As a matter of fact, it is has been shown that the false positive rate is the true limiting factor for the performance of IDS, and that in order to substantially increase the Bayesian detection rate, P(Intrusion/Alarm), the IDS must have a very low false positive rate (e.g., as low as 10(-5) or even lower). In this paper we present McPAD (multiple classifier payload-based anomaly detector), a new accurate payload-based anomaly detection system that consists of an ensemble of one-class classifiers. We show that our anomaly detector is very accurate in detecting network attacks that bear some form of sheH-code in the malicious payload. This holds true even in the case of polymorphic attacks and for very low false positive rates. Furthermore, we experiment with advanced polymorphic blending attacks and we show that in some cases even in the presence of such sophisticated attacks and for a low false positive rate our IDS still has a relatively high detection rate. (C) 2008 Elsevier B.V. All rights reserved.
引用
收藏
页码:864 / 881
页数:18
相关论文
共 50 条
  • [1] POCAD: a Novel Payload-based One-Class Classifier for Anomaly Detection
    Xuan Nam Nguyen
    Dai Tho Nguyen
    Long Hai Vu
    [J]. 2016 3RD NATIONAL FOUNDATION FOR SCIENCE AND TECHNOLOGY DEVELOPMENT CONFERENCE ON INFORMATION AND COMPUTER SCIENCE (NICS), 2016, : 74 - 79
  • [2] Payload-based anomaly detection using KPCA
    Jia, Libin
    Ma, Jun
    Li, Lin
    [J]. PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE OF MANAGEMENT ENGINEERING AND INFORMATION TECHNOLOGY, VOLS 1 AND 2, 2009, : 566 - 569
  • [3] PU Learning in Payload-based Web Anomaly Detection
    Luo, Yuxuan
    Cheng, Shaoyin
    Liu, Chong
    Jiang, Fan
    [J]. 2018 THIRD INTERNATIONAL CONFERENCE ON SECURITY OF SMART CITIES, INDUSTRIAL CONTROL SYSTEM AND COMMUNICATIONS (SSIC), 2018,
  • [4] Effective Dimensionality Reduction of Payload-Based Anomaly Detection in TMAD Model for HTTP Payload
    Kakavand, Mohsen
    Mustapha, Norwati
    Mustapha, Aida
    Abdullah, Mohd Taufik
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (08): : 3884 - 3910
  • [5] An improved payload-based anomaly detector for web applications
    Jin, Xiaohui
    Cui, Baojiang
    Li, Dong
    Cheng, Zishuai
    Yin, Congxin
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 106 : 111 - 116
  • [6] Anomalous payload-based network intrusion detection
    Wang, K
    Stolfo, SJ
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS, 2004, 3224 : 203 - 222
  • [7] Automatically Generating Payload-based Models for Botnet Detection
    Lee, Chung-Nan
    Chou, Fred
    Chen, C. M.
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON SMART CITY/SOCIALCOM/SUSTAINCOM (SMARTCITY), 2015, : 1038 - 1044
  • [8] Anomalous payload-based worm detection and signature generation
    Wang, K
    Cretu, G
    Stolfo, SJ
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, 2006, 3858 : 227 - 246
  • [9] Cyber-Critical Infrastructure Protection Using Real-Time Payload-Based Anomaly Detection
    Duessel, Patrick
    Gehl, Christian
    Laskov, Pavel
    Busser, Jens-Uwe
    Stoermann, Christof
    Kaestner, Jan
    [J]. CRITICAL INFORMATION INFRASTRUCTURES SECURITY, 2010, 6027 : 85 - +
  • [10] Using an ensemble of one-class SVM classifiers to harden payload-based anomaly detection systems
    Perdisci, Roberto
    Gu, Guofei
    Lee, Wenke
    [J]. ICDM 2006: SIXTH INTERNATIONAL CONFERENCE ON DATA MINING, PROCEEDINGS, 2006, : 488 - 498