A parameterless learning algorithm for behavior-based detection

Can Wang, Yaokai Feng, Junpei Kawamoto, Yoshiaki Hori, Kouichi Sakurai

研究成果: Chapter in Book/Report/Conference proceedingConference contribution

1 被引用数 (Scopus)

抄録

The frequency and the extent of damages caused by network attacks have been actually increasing greatly in recent years, although many approaches to avoiding and detecting attacks have been proposed in the community of network security. Thus, how to fast detect actual or potential attacks has become an urgent issue. Among the detection strategies, behavior-based ones, which use normal access patterns learned from reference data (e.g., History traffic) to detect new attacks, have attracted attention from many researchers. In each of all such strategies, a learning algorithm is necessary and plays a key role. Obviously, whether the learning algorithm can extract the normal behavior modes properly or not directly influence the detection result. However, some parameters have to determine in advance in the existing learning algorithms, which is not easy, even not feasible, in many actual applications. For example, even in the newest learning algorithm, which called FHST learning algorithm in this study, two parameters are used and they are difficult to be determined in advance. In this study, we propose a parameter less learning algorithm for the first time, in which no parameters are used. The efficiency of our proposal is verified by experiment. Although the proposed learning algorithm in this study is designed for detecting port scans, it is obviously able to be used to other behavior-based detections.

本文言語英語
ホスト出版物のタイトルProceedings - 2014 9th Asia Joint Conference on Information Security, AsiaJCIS 2014
出版社Institute of Electrical and Electronics Engineers Inc.
ページ11-18
ページ数8
ISBN(電子版)9781479957330
DOI
出版ステータス出版済み - 1 26 2014
イベント2014 9th Asia Joint Conference on Information Security, AsiaJCIS 2014 - Wuchang, Wuhan, 中国
継続期間: 9 4 20149 5 2014

出版物シリーズ

名前Proceedings - 2014 9th Asia Joint Conference on Information Security, AsiaJCIS 2014

その他

その他2014 9th Asia Joint Conference on Information Security, AsiaJCIS 2014
国/地域中国
CityWuchang, Wuhan
Period9/4/149/5/14

All Science Journal Classification (ASJC) codes

  • コンピュータ ネットワークおよび通信
  • 情報システム
  • 安全性、リスク、信頼性、品質管理

フィンガープリント

「A parameterless learning algorithm for behavior-based detection」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル