An attack-norm separation approach for detecting cyber attacks

被引:6
作者
Ye, Nong [1 ]
Farley, Toni [1 ]
Lakshminarasimhan, Deepak [1 ]
机构
[1] Arizona State Univ, Informat Syst Assurance Lab, Tempe, AZ 85287 USA
关键词
cyber attacks; intrusion detection; computer and network security; signal processing; signal detection;
D O I
10.1007/s10796-006-8731-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The two existing approaches to detecting cyber attacks on computers and networks, signature recognition and anomaly detection, have shortcomings related to the accuracy and efficiency of detection. This paper describes a new approach to cyber attack (intrusion) detection that aims to overcome these shortcomings through several innovations. We call our approach attack-norm separation. The attack-norm separation approach engages in the scientific discovery of data, features and characteristics for cyber signal (attack data) and noise (normal data). We use attack profiling and analytical discovery techniques to generalize the data, features and characteristics that exist in cyber attack and norm data. We also leverage well-established signal detection models in the physical space (e.g., radar signal detection), and verify them in the cyberspace. With this foundation of information, we build attack-norm separation models that incorporate both attack and norm characteristics. This enables us to take the least amount of relevant data necessary to achieve detection accuracy and efficiency. The attack-norm separation approach considers not only activity data, but also state and performance data along the cause-effect chains of cyber attacks on computers and networks. This enables us to achieve some detection adequacy lacking in existing intrusion detection systems.
引用
收藏
页码:163 / 177
页数:15
相关论文
共 30 条
[1]  
[Anonymous], 1999, APPL MULTIVARIATE AN
[2]  
[Anonymous], ACM Trans. Inf. Syst. Secur, DOI DOI 10.1145/322510.322526
[3]   Signal detection in underwater sound using wavelets [J].
Bailey, TC ;
Sapatinas, T ;
Powell, KJ ;
Krzanowski, WJ .
JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 1998, 93 (441) :73-83
[4]   A real-time earthquake detector with prefiltering by wavelets [J].
Botella, F ;
Rosa-Herranz, J ;
Giner, JJ ;
Molina, S ;
Galiana-Merino, JJ .
COMPUTERS & GEOSCIENCES, 2003, 29 (07) :911-919
[5]  
Box GEP, 1997, STAT CONTROL MONITOR
[6]   Recent developments in the core of digital signal processing [J].
Chen, TH ;
Vaidyanathan, PP ;
Haykin, S ;
Cohen, L ;
Maragos, P .
IEEE SIGNAL PROCESSING MAGAZINE, 1999, 16 (01) :16-31
[7]  
FAN W, P 1 IEEE INT C DAT M
[8]  
GARVEY T, 1991, 14 NAT COMP SOC C NC
[9]  
GHOSH A, 1999, 1 USENIX WORKSH INTR
[10]   Statistical pattern recognition: A review [J].
Jain, AK ;
Duin, RPW ;
Mao, JC .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2000, 22 (01) :4-37