McPAD: A multiple classifier system for accurate payload-based anomaly detection

被引:138
|
作者
Perdisci, Roberto [1 ,2 ]
Ariu, Davide [3 ]
Fogla, Prahlad [4 ]
Giacinto, Giorgio [3 ]
Lee, Wenke [2 ]
机构
[1] Damballa Inc, Atlanta, GA 30308 USA
[2] Georgia Inst Technol, Coll Comp, Atlanta, GA 30308 USA
[3] Univ Cagliari, Dept Elect & Elect Engn, I-09123 Cagliari, Italy
[4] Google Inc, Mountain View, CA 94043 USA
关键词
Network intrusion detection; Anomaly detection; Shell-code attacks; Multiple classifiers; One-class SVM; INTRUSION DETECTION; ENSEMBLE; SUPPORT;
D O I
10.1016/j.comnet.2008.11.011
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly-based network intrusion detection systems (IDS) are valuable tools for the defense-in-depth of computer networks. Unsupervised or unlabeled learning approaches for network anomaly detection have been recently proposed. Such anomaly-based network IDS are able to detect (unknown) zero-day attacks, although much care has to be dedicated to controlling the amount of false positives generated by the detection system. As a matter of fact, it is has been shown that the false positive rate is the true limiting factor for the performance of IDS, and that in order to substantially increase the Bayesian detection rate, P(Intrusion/Alarm), the IDS must have a very low false positive rate (e.g., as low as 10(-5) or even lower). In this paper we present McPAD (multiple classifier payload-based anomaly detector), a new accurate payload-based anomaly detection system that consists of an ensemble of one-class classifiers. We show that our anomaly detector is very accurate in detecting network attacks that bear some form of sheH-code in the malicious payload. This holds true even in the case of polymorphic attacks and for very low false positive rates. Furthermore, we experiment with advanced polymorphic blending attacks and we show that in some cases even in the presence of such sophisticated attacks and for a low false positive rate our IDS still has a relatively high detection rate. (C) 2008 Elsevier B.V. All rights reserved.
引用
收藏
页码:864 / 881
页数:18
相关论文
共 50 条
  • [41] Rangegram: A Novel Payload based Anomaly Detection Technique Against Web Traffic
    Swarnkar, Mayank
    Hubballi, Neminath
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNCATIONS SYSTEMS (ANTS), 2015,
  • [42] Ensemble Methods Classifier Comparison for Anomaly Based Intrusion Detection System on CIDDS-002 Dataset
    Ainurrochman
    Nugroho, Arianto
    Wahyuwidayat, Raditia
    Sianturi, Santi Tiodora
    Fauzi, Muhamad
    Ramadhan, M. Febrianto
    Pratomo, Baskoro Adi
    Shiddiqi, Ary Mazharuddin
    [J]. PROCEEDINGS OF 2021 13TH INTERNATIONAL CONFERENCE ON INFORMATION & COMMUNICATION TECHNOLOGY AND SYSTEM (ICTS), 2021, : 62 - 67
  • [43] Anomaly Based Intrusion Detection in Wireless Networks Using Bayesian Classifier
    Klassen, Myungsook
    Yang, Ning
    [J]. 2012 IEEE FIFTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATIONAL INTELLIGENCE (ICACI), 2012, : 257 - 264
  • [44] A novel unsupervised anomaly detection based on robust principal component classifier
    Qiu, Wenbin
    Wu, Yu
    Wang, Guoyin
    Yang, Simon X.
    Bai, Jie
    Li, Jieying
    [J]. DATA MINING, INTRUSION DETECTION, INFORMATION ASSURANCE, AND DATA NETWORKS SECURITY 2006, 2006, 6241
  • [45] A network-based anomaly detection system using multiple network features
    Waizumi, Yuji
    Sato, Yohei
    Nemoto, Yoshiaki
    [J]. WEBIST 2007: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, VOL IT: INTERNET TECHNOLOGY, 2007, : 410 - +
  • [46] Growing structure multiple model system based anomaly detection for crankshaft monitoring
    Liu, Jianbo
    Sun, Pu
    Djurdjanovic, Dragan
    Marko, Kenneth
    Ni, Jun
    [J]. ADVANCES IN NEURAL NETWORKS - ISNN 2006, PT 3, PROCEEDINGS, 2006, 3973 : 396 - 405
  • [47] PA2Dnet based ensemble classifier for the detection of crowd anomaly detection
    Prasad K.N.S.S.V.
    Haritha D.
    [J]. Multimedia Tools and Applications, 2024, 83 (18) : 53635 - 53653
  • [48] Lightweight and Accurate DNN-Based Anomaly Detection at Edge
    Zhang, Qinglong
    Han, Rui
    Xin, Gaofeng
    Liu, Chi Harold
    Wang, Guoren
    Chen, Lydia Y.
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2022, 33 (11) : 2927 - 2942
  • [49] Graph based Tensor Recovery For Accurate Internet Anomaly Detection
    Xie, Kun
    Li, Xiaocan
    Wang, Guanxin
    Xie, Gaogang
    Wen, Jigang
    Zhang, Dafang
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2018), 2018, : 1502 - 1510
  • [50] MCAD: Multiple connection based anomaly detection
    He, Xin
    Parameswaran, Sri
    [J]. 2008 11TH IEEE SINGAPORE INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS (ICCS), VOLS 1-3, 2008, : 999 - 1004