Adaptive Naive Bayes method for masquerade detection

Adaptive Naive Bayes method for masquerade detection
复制标题

DOI:
10.1002/sec.168
复制
发表时间:
2011-04
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
S. Dash;Krupa Sagar Reddy;A. K. Pujari
S. Dash;Krupa Sagar Reddy;A. K. Pujari
中科院分区:
其他
文献类型:
--
作者:
S. Dash;Krupa Sagar Reddy;A. K. Pujari

文献摘要

被引文献

相似文献

最近,研究人员提出了有效的检测机制伪装攻击。这些技术中的大多数使用机器学习方法来学习用户的行为模式,并检查观察到的行为是否符合用户的学习行为。当观察到的特定用户的行为与该用户过去数据的学习模式不匹配时,检测到伪装攻击。这个过程中的一个主要缺点是,用户可能会合法地暂时偏离其过去的行为。如果偏差很大并且几乎是永久性的,则期望在检测机构中捕获这样的偏差。在本文中,我们提出了一种方法,考虑到这方面的用户行为,同时检测伪装攻击。我们的方案是基于这样的前提下,一个合法的用户或攻击者使用的命令可能不同于训练的签名。但是合法用户的偏差是暂时的,而攻击者的偏差持续时间更长。通过在检测机制中引入这种新的概念,性能得到了改善。我们使用几个基准数据集来证明这一点。版权所有© 2010约翰威利父子有限公司.
Recently, researchers have proposed efficient detection mechanisms for masquerade attacks. Most of these techniques use machine learning methods to learn the behavioral patterns of users and to check if an observed behavior conforms to the learnt behavior of a user. Masquerade attack is detected when the observed behavior, reportedly of a specific user, does not match with the learnt pattern of this user's past data. A major shortcoming in this process is that the user may legitimately deviate temporarily from its past behavior. If the deviation is large and near-permanent, it is desirable that such deviations are captured in a detection mechanism. We propose, in this paper, a method that takes into consideration this aspect of user behavior while detecting masquerade attacks. Our scheme is based on the premise that the commands used by a legitimate user or an attacker may differ from the trained signature. But the deviation of the legitimate user is momentary whereas that of an attacker persists longer. By introducing this novel concept in the detection mechanism, the performance improves. We show this empirically using several benchmark datasets. Copyright © 2010 John Wiley & Sons, Ltd.