Back to Search Start Over

Effective Intrusion Type Identification with Edit Distance for HMM-Based Anomaly Detection System.

Authors :
Pal, Sankar K.
Bandyopadhyay, Sanghamitra
Biswas, Sambhunath
Koo, Ja-Min
Cho, Sung-Bae
Source :
Pattern Recognition & Machine Intelligence; 2005, p222-228, 7p
Publication Year :
2005

Abstract

As computer security becomes important, various system security mechanisms have been developed. Especially anomaly detection using hidden Markov model has been actively exploited. However, it can only detect abnormal behaviors under predefined threshold, and it cannot identify the type of intrusions. This paper aims to identify the type of intrusions by analyzing the state sequences using Viterbi algorithm and calculating the distance between the standard state sequence of each intrusion type and the current state sequence. Because the state sequences are not always extracted consistently due to environmental factors, edit distance is utilized to measure the distance effectively. Experimental results with buffer overflow attacks show that it identifies the type of intrusions well with inconsistent state sequences. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISBNs :
9783540305064
Database :
Complementary Index
Journal :
Pattern Recognition & Machine Intelligence
Publication Type :
Book
Accession number :
32965645
Full Text :
https://doi.org/10.1007/11590316_30