CAREER: Adaptive Intrusion Detection Systems
CAREER: Adaptive Intrusion Detection Systems
批准号:
0133629
负责人:
Wenke Lee
金额:
$35.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-15 至 2008-07-31
中文摘要
入侵检测是纵深防御网络安全机制的重要组成部分。针对现有入侵检测系统不能有效抵抗新的、复杂的攻击,本课题的主要研究目标是开发自适应入侵检测系统的算法、工具和系统架构。自适应入侵检测系统需要检测新的攻击,并根据正常操作的变化进行调整。为此,研究了一种基于信息论的异常检测框架。该方法首先利用信息论度量计算正常数据的正则性,然后根据正则性度量选择特征并构建检测模型。一个自适应的入侵检测系统还需要自我监控其运行时的工作负载和性能,并在有限的资源下动态地重新配置其组件以提供最佳的检测能力。为此,研究人员和实践者可以通过出版物、算法和工具来了解自适应入侵检测系统的优点和技术。本研究还在可生存网络系统、智能导航等相关领域做出了重要贡献。最终,社会将受益于更有效和更强大的安全机制。
英文摘要
Intrusion detection is a critical component of the defense-in-depthnetwork security mechanisms. Current intrusion detection systems(IDSs) are ineffective against new and sophisticated attacks.The key objective of this research project is to develop thealgorithms, tools, and system architecture for adaptive IDSs. Anadaptive IDS needs to detect new attacks and adjust to changes innormal operations. Towards this end, an information-theoretic basedanomaly detection framework is investigated. The approach is to firstcompute the regularity of normal data using information-theoreticmeasures, then select features and construct a detection modelaccording to the regularity measures. An adaptive IDS needs to alsoself-monitor its run-time workload and performance, and dynamicallyreconfigure its components to provide the best detection capabilitygiven the limited resources. Towards this end, performance monitoring,load-shedding, attack scenario analysis, and cost-benefit analysistechniques are investigated.Through the publications and algorithms and tools from this research,researchers and practitioners can learn the benefits and techniques ofadaptive IDSs. This research also makes important contributions torelated fields, e.g., survivable network systems and smartauditing. Ultimately, the society will benefit from the more effectiveand robust security mechanisms.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
2015 Cyber Security Education Workshop
-
批准号:1544099
-
项目类别:Standard Grant
-
资助金额:$3.5万
-
财政年份:2015
-
负责人:Wenke Lee
-
依托单位:
TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
-
批准号:1409807
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2014
-
负责人:Wenke Lee
-
依托单位:
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
-
批准号:1409635
-
项目类别:Standard Grant
-
资助金额:$110.0万
-
财政年份:2014
-
负责人:Wenke Lee
-
依托单位:
EAGER: The Conceptual Landscape of Information Manipulation
-
批准号:1255453
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2012
-
负责人:Wenke Lee
-
依托单位:
SaTC Cyber Cafe
-
批准号:1304678
-
项目类别:Standard Grant
-
资助金额:$5.34万
-
财政年份:2012
-
负责人:Wenke Lee
-
依托单位:
TC: Small: A Foundational and Practical Platform for Host Security Applications
-
批准号:1017265
-
项目类别:Standard Grant
-
资助金额:$42.96万
-
财政年份:2010
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
-
批准号:0831300
-
项目类别:Continuing Grant
-
资助金额:$66.89万
-
财政年份:2008
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
-
批准号:0716570
-
项目类别:Continuing Grant
-
资助金额:$22.0万
-
财政年份:2007
-
负责人:Wenke Lee
-
依托单位:
Collaborative Research: CT-ISG: Modeling and Measuring Botnets
-
批准号:0627477
-
项目类别:Continuing Grant
-
资助金额:$17.5万
-
财政年份:2006
-
负责人:Wenke Lee
-
依托单位:
Intrusion Detection Techniques for Mobile Ad Hoc Networks
-
批准号:0311024
-
项目类别:Continuing Grant
-
资助金额:$27.5万
-
财政年份:2003
-
负责人:Wenke Lee
-
依托单位:
海外基金