|
|
|
|
Moving Dispersion Method for Statistical Anomaly Detection in Intrusion Detection Systems
|
|
|
|
|
|
|
|
نویسنده
|
Golic Jovan Dj.
|
|
منبع
|
the isc international journal of information security - 2009 - دوره : 1 - شماره : 2 - صفحه:71 -91
|
|
چکیده
|
A unied method for statistical anomaly detection in intrusion detectionsystems is theoretically introduced. it is based on estimating a dispersion measure of numerical or symbolic data on successive moving windows in time and nding the times when a relative change of the dispersion measureis signicant. appropriate dispersion measures, relative differences, moving windows, as well as techniques for their effcient estimation are proposed. inparticular, the method can be used for detecting network traffic anomalies dueto network failures and network attacks such as (distributed) denial of service attacks, scanning attacks, spam and spit attacks, and massive malicious software attacks.
|
|
کلیدواژه
|
Intrusion detection ,Statisticalanomaly detection ,Dispersionmeasure ,Concentration measure ,Variance ,Linear regression ,EWMA techniques
|
|
آدرس
|
Security Innovation, Italy
|
|
پست الکترونیکی
|
jovan.golic@telecomitalia.it
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|