Detecting anomalous network traffic with self-organizing maps

被引:0
作者
Ramadas, M [1 ]
Ostermann, S
Tjaden, B
机构
[1] Ohio Univ, Athens, OH 45701 USA
[2] James Madison Univ, Harrisonburg, VA 22807 USA
来源
RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS | 2003年 / 2820卷
关键词
intrusion detection; anomaly detection; self-organizing maps;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Integrated Network-Based Ohio University Network Detective Service (INBOUNDS) is a network based intrusion detection system being developed at Ohio University. The Anomalous Network-Traffic Detection with Self Organizing Maps (ANDSOM) module for INBOUNDS detects anomalous network traffic based on the Self-Organizing Map algorithm. Each network connection is characterized by six parameters and specified as a six-dimensional vector. The ANDSOM module creates a Self-Organizing Map (SOM) having a two-dimensional lattice of neurons for each network service. During the training phase, normal network traffic is fed to the ANDSOM module, and the neurons in the SOM are trained to capture its characteristic patterns. During real-time operation, a network connection is fed to its respective SOM, and a "winner" is selected by finding the neuron that is closest in distance to it. The network connection is then classified as an intrusion if this distance is more than a pre-set threshold.
引用
收藏
页码:36 / 54
页数:19
相关论文
共 18 条
  • [1] [Anonymous], P ISOC S NETW DISTR
  • [2] Berners-Lee Tim, 1996, Hypertext transfer protocol-HTTP/1.0
  • [3] BLANTON E, TCPURIFY
  • [4] Cannady J., 1998, P 1 REC ADV INTR DET
  • [5] Fielding R., 1999, Tech. Rep
  • [6] HOLLMEN J, PRINCIPAL COMPONENT
  • [7] *ISC BIND TSIG, VU196945 ISC BIND TS
  • [8] JIRAPUMMIN C, 2002, HYBRID NEURAL NETWOR
  • [9] Kohonen T., 2001, INFORM SCIENCES
  • [10] LICHODZIJEWSKI P, 2002, IEEE WORLD C COMP IN