Locality-based profile analysis for secondary intrusion detection

被引:0
|
作者
Zhou, M [1 ]
Lee, R [1 ]
Lang, SD [1 ]
机构
[1] Univ Cent Florida, Sch Elect Engn & Comp Sci, Orlando, FL 32816 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
While a firewall at the perimeter of a local network provides the first line of defense against attackers, many intrusion incidents result from successftd penetration of the firewall. The compromise of one computer puts the entire network at risk. We propose a distributed personal Intrusion Detection System (IDS) that provides local anomaly detection as well as centralized traffic analysis. The system first builds profiles for normal network activity and then labels as suspicious any events that deviate from the normal profiles. The normal profiles are based on variations in connection-based behavior at each individual host. Deviations at each host are recorded using a local weight assignment scheme and then further processed by the central analyzer to build a weighted link graph representing the overall network abnormality. As local networks become more vulnerable to inside attack, our system reinforces security to prevent corruption from the inside.
引用
收藏
页码:166 / 171
页数:6
相关论文
共 50 条
  • [21] Search and index in locality-based clustering overlay
    He, Y
    Zhang, JZ
    Niu, XG
    Zhao, Q
    2005 IEEE International Symposium on Cluster Computing and the Grid, Vols 1 and 2, 2005, : 229 - 236
  • [22] GeoChain: A Locality-Based Sharding Protocol for Permissioned Blockchains
    Mao, Chunyu
    Golab, Wojciech
    PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, ICDCN 2023, 2023, : 70 - 79
  • [23] An analytical model of locality-based parallel irregular reductions
    Gutierrez, Eladio
    Plata, Oscar
    Zapata, Emilio L.
    PARALLEL COMPUTING, 2008, 34 (03) : 133 - 157
  • [24] A comparison of locality-based and recency-based replacement policies
    Vandierendonck, H
    De Bosschere, K
    HIGH PERFORMANCE COMPUTING, PROCEEDINGS, 2000, 1940 : 310 - 318
  • [25] Locality-Based Graph Clustering of Spatially Embedded Time Series
    Maschler, Fabian
    Geier, Fabian
    Bookhagen, Bodo
    Mueller, Emmanuel
    COMPLEX NETWORKS & THEIR APPLICATIONS VI, 2018, 689 : 719 - 730
  • [26] Locality-based Electromagnetic Leakage Assessment Using CNN
    Heffron, Ian
    Dean, James
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY ICCWS, 2023, : 570 - 576
  • [27] LOCALITY-BASED DISCRIMINANT FEATURE SELECTION WITH TRACE RATIO
    Guo, Muhan
    Yang, Sheng
    Nie, Feiping
    Li, Xuelong
    2018 25TH IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2018, : 3373 - 3377
  • [28] Effective document presentation with a locality-based similarity heuristic
    de Kretser, O
    Moffat, A
    SIGIR'99: PROCEEDINGS OF 22ND INTERNATIONAL CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 1999, : 113 - 120
  • [29] Semantic locality-based approximate knowledge graph query
    Wang, Yuxiang
    Ge, Zhangpeng
    Yan, Haijiang
    Xu, Xiaoliang
    Xia, Yixing
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (24):
  • [30] Dealing with syntactic variation through a locality-based approach
    Vilares, J
    Alonso, MA
    STRING PROCESSING AND INFORMATION RETRIEVAL, PROCEEDINGS, 2004, 3246 : 255 - 266