Intrusion Detection in Unstructured Contexts Using On-line Clustering and Novelty Detection
Author(s) -
Eduardo Alves Ferreira,
Rodrigo Fernandes de Mello
Publication year - 2013
Publication title -
revista de informática teórica e aplicada
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.11
H-Index - 1
eISSN - 2175-2745
pISSN - 0103-4308
DOI - 10.22456/2175-2745.26211
Subject(s) - novelty detection , intrusion detection system , computer science , cluster analysis , context (archaeology) , novelty , data mining , artificial intelligence , pattern recognition (psychology) , paleontology , philosophy , theology , biology
The characterization of processes behavior is usually considered whenperforming intrusion detection. Several works characterize specific aspects of systemsand attempt to detect novelties in that context, associating observed anomalies to at-tack events. Such approach is limited or even useless when the observed context isunstructured, i.e. when the monitor generates text-based log files or a variable numberof application attributes. In order to overcome such drawback, this paper considersthe use of single-pass clustering techniques to quantize unstructured data and generatetime series, using algorithms with low computational complexity, applicable in a real-world scenario. Afterward, novelty detection techniques are employed on such seriesto distinguish behavior anomalies, which are associated with intrusions. We evaluatedthe approach using a system characterization dataset and confirmed that it aggregatescontext information to represent the behavior of applications as time series, wherenovelty detection can be successfully performed.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom