A New Two-Stage Search Procedure for Misuse Detection

被引:0
|
作者
Petrovic, Slobodan [1 ]
Franke, Katrin [1 ]
机构
[1] Gjovik Univ Coll, Dept Comp Sci & Media Technol, NISlab, POB 191, N-2802 Gjovik, Norway
关键词
Intrusion Detection; Misuse Detection; Constrained Edit Distance; Search;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A new two-stage indexless search procedure is presented that makes use of the constrained edit distance in IDS misuse detection attack database search. The procedure consists of a pre-selection phase, in which the original dataset is reduced and the exhaustive search phase for the database records selected in the first phase. The maximum number of consecutive deletions represents the constraint. Besides eliminating the need for finer exhaustive search in the attack database records in which the detected subsequence is too distorted, the new search procedure also enables better control over the search process in the case of deliberate distortion of the attack strings. Experimental results obtained on the SNORT signature files show that the proposed method offers average search data set reduction in the typical cases of more than 70% compared to the method that uses the unconstrained edit distance.
引用
收藏
页码:55 / 62
页数:8
相关论文
共 50 条
  • [1] A new two-stage search procedure for misuse detection
    Petrovic, Slobodan
    Franke, Katrin
    [J]. PROCEEDINGS OF FUTURE GENERATION COMMUNICATION AND NETWORKING, WORKSHOP PAPERS, VOL 2, 2007, : 421 - 425
  • [2] A Two-Stage Procedure of Radar Target Detection
    Galushko, Vladimir G.
    [J]. 2016 9TH INTERNATIONAL KHARKIV SYMPOSIUM ON PHYSICS AND ENGINEERING OF MICROWAVES, MILLIMETER AND SUBMILLIMETER WAVES (MSMW), 2016,
  • [3] An optimal two-stage graphical search planning procedure for submerged targets
    Pham-Gia, T
    Turkkan, N
    [J]. MATHEMATICAL AND COMPUTER MODELLING, 2002, 36 (1-2) : 217 - 230
  • [4] Two-stage procedure for transportation mode detection based on sighting data
    Chen, Huey-Kuo
    Ho, Hsiao-Chingki
    Wu, Luo-Yu
    Lee, Ian
    Chou, Huey-Wen
    [J]. TRANSPORTMETRICA A-TRANSPORT SCIENCE, 2024, 20 (01) : 36 - 36
  • [5] An enhanced two-stage selection procedure
    Chen, EJ
    Kelton, WD
    [J]. PROCEEDINGS OF THE 2000 WINTER SIMULATION CONFERENCE, VOLS 1 AND 2, 2000, : 727 - 735
  • [6] A two-stage packing problem procedure
    Moura, Ana
    Bortfeldt, Andreas
    [J]. INTERNATIONAL TRANSACTIONS IN OPERATIONAL RESEARCH, 2017, 24 (1-2) : 43 - 58
  • [7] A two-stage stepwise estimation procedure
    Chen, John T.
    [J]. BIOMETRICS, 2008, 64 (02) : 406 - 412
  • [8] Two-stage production of OSB flakes, an alternative procedure: New outcomes
    Loth, R
    Thole, V
    [J]. 37th International Wood Composite Materials Symposium Proceedings, 2003, : 149 - 150
  • [9] A two-stage procedure for partially identified models
    Kaido, Hiroaki
    White, Halbert
    [J]. JOURNAL OF ECONOMETRICS, 2014, 182 (01) : 5 - 13
  • [10] Laparoscopic two-stage procedure for gallstone ileus
    Inukai, Koichi
    Tsuji, Eri
    Takashima, Nobuhiro
    Yamamoto, Minoru
    [J]. JOURNAL OF MINIMAL ACCESS SURGERY, 2019, 15 (02) : 164 - 166