2010
DOI: 10.1002/nem.748
|View full text |Cite
|
Sign up to set email alerts
|

A scalable, efficient and informative approach for anomaly‐based intrusion detection systems: theory and practice

Abstract: SUMMARYIn this paper, we present the design and implementation of a new approach for anomaly detection and classification over high speed networks. The proposed approach is based first of all on a data reduction phase through flow sampling by focusing mainly on short lived flows. The second step is then a random aggregation of some descriptors such as a number of SYN packets per flow in two different data structures called Count Min Sketch and Multi-Layer Reversible Sketch. A sequential change point detection … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

1
49
0

Year Published

2012
2012
2019
2019

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 40 publications
(50 citation statements)
references
References 51 publications
1
49
0
Order By: Relevance
“…In general they act on monodimensional time series and, to consider different traffic features, the same basic algorithm is sequentially repeated [2], [3], [1]. The above-mentioned papers represent the starting point for the present work, which extended the structure of the IDS described in [1] to operate with vectorial sequences.…”
Section: Related Workmentioning
confidence: 99%
See 4 more Smart Citations
“…In general they act on monodimensional time series and, to consider different traffic features, the same basic algorithm is sequentially repeated [2], [3], [1]. The above-mentioned papers represent the starting point for the present work, which extended the structure of the IDS described in [1] to operate with vectorial sequences.…”
Section: Related Workmentioning
confidence: 99%
“…Sketches can not be considered as a detection method, nevertheless they can be used as a building block of several AD systems [12], [13], [15], [14], [16], [17], [18], [19], [2], [1]. Indeed, the use of sketches corresponds to a random aggregation that "efficiently" reduces the dimension of the data (wrt other deterministic aggregations, such as according to input/output routers [17]); moreover, the use of reversible sketches [20] permits to trace back the flows responsible for the anomalies.…”
Section: Related Workmentioning
confidence: 99%
See 3 more Smart Citations