Normal Profile Updating Method for Enhanced Packet Header Anomaly Detection

被引:0
|
作者
Alsharafi, Walid Mohamed [1 ,2 ]
Omar, Mohd Nizam [1 ]
Al-Majmar, Nashwan Ahmed [2 ]
Fazea, Yousef [1 ]
机构
[1] Univ Utara Malaysia UUM, Sch Comp, InterNetworks Res Lab, Sintok 06010, Kedah, Malaysia
[2] Ibb Univ, Fac Sci, Dept Comp Sci & Informat Technol, Ibb, Yemen
来源
EMERGING TRENDS IN INTELLIGENT COMPUTING AND INFORMATICS: DATA SCIENCE, INTELLIGENT INFORMATION SYSTEMS AND SMART COMPUTING | 2020年 / 1073卷
关键词
IDS; PHAD; Anomaly detection; Normal profile; False alarm; NETWORK;
D O I
10.1007/978-3-030-33582-3_69
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
There is a significant need for various Intrusion Detection Systems (IDS) methods for packet behavior anomaly detection, due to the consistent exposure of packets to frequent intrusion threats. Thus, Packet Header Anomaly Detection (PHAD) considered as one of many significant approaches that is used for detecting threats on network packet. However, this approach still suffers from high generation of false alarm rate. This paper investigates a Normal Profile Updating Method (NPUM) for enhancing the PHAD based IDS model. This method updates normal profile of anomaly IDS using further processing of both the normal and abnormal data identified by anomaly detector. Simulation experiments and DARPA intrusion detection evaluation data sets are used for testing the proposed method. Results show that the proposed method can reduce the false positive alarms and improve the performance in terms of accuracy of detection. The major contributions of this research include the design of an enhanced PHAD-based IDS. This would contribute toward the enhanced IDSs to strengthen network security.
引用
收藏
页码:734 / 747
页数:14
相关论文
共 50 条
  • [1] PHAD: Packet Header Anomaly Detection
    Garg, Akash
    Maheshwari, Prachi
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND CONTROL (ISCO'16), 2016,
  • [2] Packet Header Anomaly Detection Using Statistical Analysis
    Yassin, Warusia
    Udzir, Nur Izura
    Abdullah, Azizol
    Abdullah, Mohd Taufik
    Muda, Zaiton
    Zulzalil, Hazura
    INTERNATIONAL JOINT CONFERENCE SOCO'14-CISIS'14-ICEUTE'14, 2014, 299 : 473 - 482
  • [3] Modeling protocol based packet header anomaly detector for network and host intrusion detection systems
    Shamsuddin, Solahuddin B.
    Woodward, Michael E.
    CRYPTOLOGY AND NETWORK SECURITY, 2007, 4856 : 209 - 227
  • [4] Packet header parsing method in high speed network intrusion detection system
    Xiao, Y. (xydarcher@uestc.edu.cn), 1600, Science Press (33):
  • [5] A New Network Anomaly Detection Method Based on Header Information Using Greedy Algorithm
    Ates, Cagalay
    Ozdel, Suleyman
    Anarim, Eniin
    2019 6TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT 2019), 2019, : 657 - 662
  • [6] WEMA to Speed up NIDS Packet Header Detection Engine
    Hnaif, Adnan A.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ADVANCED INTELLIGENT SYSTEMS AND INFORMATICS 2016, 2017, 533 : 523 - 529
  • [7] Enhanced Anomaly Detection in Compressor Components Using Deep Learning and an Attribute Updating Model
    Yang, Guotao
    Hu, Shaolin
    Wang, Longtao
    Industrial and Engineering Chemistry Research, 2024, 63 (42): : 18027 - 18042
  • [8] Enhanced Anomaly Detection in Compressor Components Using Deep Learning and an Attribute Updating Model
    Yang, Guotao
    Hu, Shaolin
    Wang, Longtao
    INDUSTRIAL & ENGINEERING CHEMISTRY RESEARCH, 2024, 63 (42) : 18027 - 18042
  • [9] Anomaly Detection for Mixed Packet Sequences
    Meghdouri, Fares
    Vazquez, Felix Iglesias
    Zseby, Tanja
    2020 IEEE 45TH LOCAL COMPUTER NETWORKS SYMPOSIUM ON EMERGING TOPICS IN NETWORKING (LCN SYMPOSIUM 2020), 2020, : 120 - 130
  • [10] Deep anomaly detection in packet payload
    Liu, Jiaxin
    Song, Xucheng
    Zhou, Yingjie
    Peng, Xi
    Zhang, Yanru
    Liu, Pei
    Wu, Dapeng
    Zhu, Ce
    NEUROCOMPUTING, 2022, 485 : 205 - 218