Inductive Intrusion Detection in Flow-Based Network Data Using One-Class Support Vector Machines

Inductive Intrusion Detection in Flow-Based Network Data Using One-Class Support Vector Machines
复制标题

DOI:
10.1109/ntms.2011.5720582
复制
发表时间:
2011-02
期刊:
2011 4th IFIP International Conference on New Technologies, Mobility and Security
影响因子:
--
通讯作者:
Philipp Winter;Eckehard Hermann;M. Zeilinger
Philipp Winter;Eckehard Hermann;M. Zeilinger
中科院分区:
其他
文献类型:
--
作者:
Philipp Winter;Eckehard Hermann;M. Zeilinger

文献摘要

被引文献

相似文献

尽管有大量的研究工作,普通的异常检测系统仍然遭受严重的缺点,如高误报率,由于网络流量的巨大变化。此外,越来越快的网络速度给基于深度数据包检测的系统带来了性能问题。在本文中,我们提出了一种新的感应式网络入侵检测系统来解决这些问题。该系统运行在轻量级的网络流,并使用一类支持向量机进行分析。与传统的异常检测系统相比,该系统使用恶意而不是良性网络数据进行训练。该系统适用于大规模网络的负载,受普通异常检测系统典型问题的影响较小。评估带来了令人满意的结果,这表明该方法是有趣的进一步研究,并完美地补充了传统的基于特征的入侵检测系统。
Despite extensive research effort, ordinary anomaly detection systems still suffer from serious drawbacks such as high false alarm rates due to the enormous variety of network traffic. Also, increasingly fast network speeds pose performance problems to systems which base upon deep packet inspection. In this paper, we address these problems by proposing a novel inductive network intrusion detection system. The system operates on lightweight network flows and uses One-Class Support Vector Machines for analysis. In contrast to traditional anomaly detection systems, the system is trained with malicious rather than with benign network data. The system is suited for the load of large-scale networks and is less affected by typical problems of ordinary anomaly detection systems. Evaluations brought satisfying results which indicate that the proposed approach is interesting for further research and perfectly complements traditional signature-based intrusion detection systems.