Conversation Exchange Dynamics: A New Signal Primitive for Computer Network Intrusion Detection
Author
McEachen, John C.
Zachary, John M.
Wang, Junling
Cheng, Kah Wai
Date
2004Metadata
Show full item recordAbstract
As distributed network intrusion detection systems expand
to integrate hundreds and possibly thousands of sensors,
managing and presenting the associated sensor data becomes
an increasingly complex task. Methods of intelligent data
reduction are needed to make sense of the wide dimensional
variations. We present a new signal primitive we call
conversation exchange dynamics (CED) that accentuates
anomalies in traffic flow. This signal provides an aggregated
primitive that may be used by intrusion detection systems to
base detection strategies upon. Indications of the signal in a
variety of simulated and actual anomalous network traffic
from distributed sensor collections are presented.
Specifically, attacks from the MIT Lawrence Livermore IDS data set are considered. We conclude that CED presents a useful signal primitive for assistance in conducting IDS.
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Collections
Related items
Showing items related by title, author, creator and subject.
-
Towed array performance in the littoral waters of Northern Australia
Crouch, James A. M (Monterey, California. Naval Postgraduate School, 1997-06);The goal of this research was to investigate the performance of low frequency passive sonars in the Arafura Sea. Sound speed profiles representative of the wet and dry monsoon seasons and geoacoustic data were inputted ... -
Exploring fields with shift registers
Radowicz, Jody L. (Monterey, California. Naval Postgraduate School, 2006-09);The S-Boxes used in the AES algorithm are generated by field extensions of the Galois field over two elements, called GF(2). Therefore, understanding the field extensions provides a method of analysis, potentially efficient ... -
Low frequency active sonar (Generic UK) performance assessment in the operationally significant area of the Northwest approaches to the United Kingdom
Hunt, Charles J. (Monterey, California. Naval Postgraduate School, 1998-09-01);The goal of this research was to make a performance assessment for a generic UK Low Frequency Active Sonar (LFAS) operating in the northwest approaches to the UK. Five diverse and operationally significant sound speed and ...