Using Pattern-of-Life as Contextual Information for Anomaly-Based Intrusion Detection Systems

Using Pattern-of-Life as Contextual Information for Anomaly-Based Intrusion Detection Systems
复制标题

DOI:
10.1109/access.2017.2762162
复制
发表时间:
2017-10
期刊:
影响因子:
3.9
通讯作者:
Francisco J. Aparicio-Navarro;K. Kyriakopoulos;Yu Gong;D. Parish;J. Chambers
Francisco J. Aparicio-Navarro;K. Kyriakopoulos;Yu Gong;D. Parish;J. Chambers
中科院分区:
计算机科学3区
文献类型:
--
作者:
Francisco J. Aparicio-Navarro;K. Kyriakopoulos;Yu Gong;D. Parish;J. Chambers

文献摘要

被引文献

相似文献

随着网络攻击的复杂性不断增加,需要开发新的健壮的检测机制。下一代入侵检测系统不仅应该能够根据可测量的网络流量,而且还应该能够根据与受保护网络相关的可用高级信息来调整其检测特性。为此,我们利用计算机网络的生活模式(POL)作为高级信息的主要来源。我们提出了两种新的方法,利用模糊认知图(FCM)将POL结合到检测过程中。这项工作有四个主要目标。第一,评估拟议方法在识别是否存在攻击方面的效率。第二,确定将FCM整合到入侵检测框架中的建议方法中的哪种方法可产生最佳结果。第三,确定在FCM设计中使用的哪种度量产生最佳的检测结果。第四,证明上下文信息在入侵检测系统中可以提供更好的检测性能。实验结果表明,根据不同的度量组合,本文提出的方法减少了虚警总数,提供了近乎完美的检测率(即99.76%)和6.33%的误检率,从而提高了入侵检测系统的有效性。
As the complexity of cyber-attacks keeps increasing, new robust detection mechanisms need to be developed. The next generation of Intrusion Detection Systems (IDSs) should be able to adapt their detection characteristics based not only on the measureable network traffic, but also on the available high-level information related to the protected network. To this end, we make use of the Pattern-of-Life (PoL) of a computer network as the main source of high-level information. We propose two novel approaches that make use of a Fuzzy Cognitive Map (FCM) to incorporate the PoL into the detection process. There are four main aims of the work. First, to evaluate the efficiency of the proposed approaches in identifying the presence of attacks. Second, to identify which of the proposed approaches to integrate an FCM into the IDS framework produces the best results. Third, to identify which of the metrics used in the design of the FCM produces the best detection results. Fourth, to evidence the improved detection performance that contextual information can offer in IDSs. The results that we present verify that the proposed approaches improve the effectiveness of our IDS by reducing the total number of false alarms; providing almost perfect detection rate (i.e., 99.76%) and only 6.33% false positive rate, depending on the particular metric combination.