TY - GEN
T1 - Intrusion detection using geometrical structure
AU - Jamdagni, Aruna
AU - Tan, Zhiyuan
AU - Nanda, Priyadarsi
AU - He, Xiangjian
AU - Liu, Ren
PY - 2009
Y1 - 2009
N2 - We propose a statistical model, namely Geometrical Structure Anomaly Detection (GSAD) to detect intrusion using the packet payload in the network. GSAD takes into account the correlations among the packet payload features arranged in a geometrical structure. The representation is based on statistical analysis of Mahalanobis distances among payload features, which calculate the similarity of new data against precomputed profile. It calculates weight factor to determine anomaly in the payload. In the 1999 DARPA intrusion detection evaluation data set, we conduct several tests for limited attacks on port 80 and port 25. Our approach establishes and identifies the correlation among packet payloads in a network.
AB - We propose a statistical model, namely Geometrical Structure Anomaly Detection (GSAD) to detect intrusion using the packet payload in the network. GSAD takes into account the correlations among the packet payload features arranged in a geometrical structure. The representation is based on statistical analysis of Mahalanobis distances among payload features, which calculate the similarity of new data against precomputed profile. It calculates weight factor to determine anomaly in the payload. In the 1999 DARPA intrusion detection evaluation data set, we conduct several tests for limited attacks on port 80 and port 25. Our approach establishes and identifies the correlation among packet payloads in a network.
KW - Geometrical structure
KW - Intusion detection
KW - Mahalanobis distance
KW - Pattern recognition
KW - Payload
UR - http://www.scopus.com/inward/record.url?scp=77949791132&partnerID=8YFLogxK
U2 - 10.1109/FCST.2009.97
DO - 10.1109/FCST.2009.97
M3 - Conference contribution
AN - SCOPUS:77949791132
SN - 9780769539324
T3 - 4th International Conference on Frontier of Computer Science and Technology, FCST 2009
SP - 327
EP - 333
BT - 4th International Conference on Frontier of Computer Science and Technology, FCST 2009
T2 - 4th International Conference on Frontier of Computer Science and Technology, FCST 2009
Y2 - 17 December 2009 through 19 December 2009
ER -