Netspot: a simple Intrusion Detection System with statistical learning

被引:4
|
作者
Siffer, Alban [1 ]
Fouque, Pierre-Alain [2 ]
Termier, Alexandre [3 ]
Largouet, Christine [4 ]
机构
[1] Univ Rennes, IRISA, CNRS, Amossys, Rennes, France
[2] Univ Rennes, IRISA, CNRS, Rennes, France
[3] Univ Rennes, IRISA, CNRS, INRIA, Rennes, France
[4] CNRS, IRISA, INRIA, AgroCampus Ouest, Rennes, France
来源
2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020) | 2020年
关键词
Network security; Intrusion detection systems; Statistical Learning;
D O I
10.1109/TrustCom50675.2020.00122
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning is nowadays increasingly used in cyber-security. While intrusion detection was mainly based on human expertise in the 1990s, learning models to predict attacks are now built from data. However, a large part of the developed learning algorithms hitherto has missed real-world issues, making them unpractical. Indeed, many supervised algorithms described in the literature have been trained and tuned only on the KDD99 dataset. Besides, these algorithms are often static and are unable to automatically adapt for detecting attacks depending on the network traffic. Consequently, we are far from detecting zero-day or more general Advanced Persistent Threats (APT) since only pre-registered and well-characterized attacks can be catched. Some recent systems use unsupervised ML algorithms, but the resulting tools are overly complex: many ML components are stacked with various tuning parameters, usually making the results hard to interpret. And finally, a strong ML/DM expertise is required to set up these systems on real networks. We present netspot, a very simple network intrusion detection system (NIDS) powered by SPOT, a recent streaming statistical anomaly detector. This statistical test uses Extreme Value Theory, which is a powerful method for detecting anomalies. Unlike all the previous works, it is not an end-to-end solution aimed to detect all cyber-attacks with packet resolution. It is rather a module providing a behavioral information which can be integrated in a more general monitoring system. netspot is simple: it has few (simple) parameters, it adapts along time to the monitored network and it is as fast as current rule-based methods. But most importantly, it is able to detect real-world cyber-attacks, making it a credible practical anomaly-based NIDS.
引用
收藏
页码:912 / 919
页数:8
相关论文
共 50 条
  • [41] Network intrusion and failure detection system with statistical analyses of packet headers
    Goto, K
    Kojima, K
    18TH INTERNATIONAL CONFERENCE ON SYSTEMS ENGINEERING, PROCEEDINGS, 2005, : 22 - 27
  • [42] A Simple Recurrent Unit Model Based Intrusion Detection System With DCGAN
    Yang, Jin
    Li, Tao
    Liang, Gang
    He, Wenbo
    Zhao, Yue
    IEEE ACCESS, 2019, 7 : 83286 - 83296
  • [43] PROPOSAL OF ALGORITHMS FOR STATISTICAL INTRUSION DETECTION
    Cisar, Petar
    Cisar, Sanja Maravic
    Ivkovic, Miodrag
    Milanov, Dusanka
    Markoski, Branko
    METALURGIA INTERNATIONAL, 2012, 17 (05): : 73 - 77
  • [44] Statistical intrusion detection in data networks
    Britos, José Daniel
    IEEE Latin America Transactions, 2007, 5 (05) : 373 - 380
  • [45] Intrusion Detection System For Manets Using Deep Learning Approach
    Sbai, Oussama
    Elboukhari, Mohamed
    International Journal of Computer Science and Applications, 2021, 18 (01) : 85 - 101
  • [46] Attack classification of an intrusion detection system using deep learning and
    Novaria Kunang, Yesi
    Nurmaini, Siti
    Stiawan, Deris
    Suprapto, Bhakti Yudho
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 58
  • [47] IDSDL: a sensitive intrusion detection system based on deep learning
    Yanjun Hu
    Fan Bai
    Xuemiao Yang
    Yafeng Liu
    EURASIP Journal on Wireless Communications and Networking, 2021
  • [48] Analysis on intrusion detection system using machine learning techniques
    Seraphim B.I.
    Poovammal E.
    Lecture Notes on Data Engineering and Communications Technologies, 2021, 66 : 423 - 441
  • [49] Comparative Study of Machine Learning Algorithm for Intrusion Detection System
    Sravani, K.
    Srinivasu, P.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON FRONTIERS OF INTELLIGENT COMPUTING: THEORY AND APPLICATIONS (FICTA) 2013, 2014, 247 : 189 - 196
  • [50] Toward Deep Learning based Intrusion Detection System: A Survey
    Li, Zhiqi
    Fang, Weidong
    Zhu, Chunsheng
    Song, Guannan
    Zhang, Wuxiong
    PROCEEDINGS OF THE 2024 6TH INTERNATIONAL CONFERENCE ON BIG DATA ENGINEERING, BDE 2024, 2024, : 25 - 32