首页    期刊浏览 2024年11月08日 星期五
登录注册

文章基本信息

  • 标题:A Multi-Stage Network Anomaly Detection Method for Improving Efficiency and Accuracy
  • 本地全文:下载
  • 作者:Yuji Waizumi ; Hiroshi Tsunoda ; Masashi Tsuji
  • 期刊名称:Journal of Information Security
  • 印刷版ISSN:2153-1234
  • 电子版ISSN:2153-1242
  • 出版年度:2012
  • 卷号:3
  • 期号:1
  • 页码:18-24
  • DOI:10.4236/jis.2012.31003
  • 出版社:Scientific Research Publishing
  • 摘要:Because of an explosive growth of the intrusions, necessity of anomaly-based Intrusion Detection Systems (IDSs) which are capable of detecting novel attacks, is increasing. Among those systems, flow-based detection systems which use a series of packets exchanged between two terminals as a unit of observation, have an advantage of being able to detect anomaly which is included in only some specific sessions. However, in large-scale networks where a large number of communications takes place, analyzing every flow is not practical. On the other hand, a timeslot-based detection systems need not to prepare a number of buffers although it is difficult to specify anomaly communications. In this paper, we propose a multi-stage anomaly detection system which is combination of timeslot-based and flow-based detectors. The proposed system can reduce the number of flows which need to be subjected to flow-based analysis but yet exhibits high detection accuracy. Through experiments using data set, we present the effectiveness of the proposed method.
  • 关键词:Network Anomaly Detection; Timeslot-Based Analysis; Flow-Based Analysis; Multi-Stage Traffic Analysis; Flow Reduction
国家哲学社会科学文献中心版权所有