An anomaly detection technique based on a chi-square statistic for detecting intrusions into information systems

被引:152
作者
Ye, N [1 ]
Chen, Q [1 ]
机构
[1] Arizona State Univ, Dept Ind Engn, Tempe, AZ 85287 USA
关键词
computer security; intrusion detection; multivariate analysis; chi-square statistic;
D O I
10.1002/qre.392
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
An intrusion into an information system compromises its security (e.g. availability, integrity and confidentiality) through a series of events in the information system. Intrusive events often show departures (anomalies) from normal events in an information system. This paper presents an anomaly detection technique based on a chi-square statistic. This technique builds a profile of normal events in an information system-a norm profile computes the departure of events in the recent past from the norm profile and detects a large departure as an anomaly-a likely intrusion. This technique was tested for its performance in distinguishing normal events from intrusive events in an information system. The test results demonstrated the promising performance of this technique for intrusion detection in terms of a low false alarm rate and a high detection rate. Intrusive events were detected at a very early stage. Copyright (C) 2001 John Wiley & Sons, Ltd.
引用
收藏
页码:105 / 112
页数:8
相关论文
共 20 条
[1]  
Anderson D., 1995, SRICSL9707
[2]  
[Anonymous], 1987, BIOSTATISTICS FDN AN
[3]  
[Anonymous], 1995, NETWORK SECURITY PRI
[4]  
Banks J.G., 1989, Principles of quality control
[5]  
Escamilla T., 1998, Intrusion detection: network security beyond the firewall
[6]   Computer immunology [J].
Forrest, S ;
Hofmeyr, SA ;
Somayaji, A .
COMMUNICATIONS OF THE ACM, 1997, 40 (10) :88-96
[7]  
GHOSH A, 1999, P 1 USENIX WORKSH IN
[8]  
HOTELLING H., 1947, Multivariate quality control. Techniques of statistical analysis
[9]  
JAVITZ H, 1994, A010 SRI INT
[10]  
Javitz H. S., 1991, P 1991 IEEE S RES SE