Back to Search Start Over

Coping with 0-Day Attacks through Unsupervised Network Intrusion Detection

Authors :
Philippe Owezarski
Pedro Casas
Johan Mazel
FTW - Telecommunication research Center (FTW)
FTW
Japanese French Laboratory for Informatics (JFLI)
National Institute of Informatics (NII)-Université Pierre et Marie Curie - Paris 6 (UPMC)-The University of Tokyo (UTokyo)-Centre National de la Recherche Scientifique (CNRS)
Équipe Services et Architectures pour Réseaux Avancés (LAAS-SARA)
Laboratoire d'analyse et d'architecture des systèmes (LAAS)
Université Toulouse Capitole (UT Capitole)
Université de Toulouse (UT)-Université de Toulouse (UT)-Institut National des Sciences Appliquées - Toulouse (INSA Toulouse)
Institut National des Sciences Appliquées (INSA)-Université de Toulouse (UT)-Institut National des Sciences Appliquées (INSA)-Université Toulouse - Jean Jaurès (UT2J)
Université de Toulouse (UT)-Université Toulouse III - Paul Sabatier (UT3)
Université de Toulouse (UT)-Centre National de la Recherche Scientifique (CNRS)-Institut National Polytechnique (Toulouse) (Toulouse INP)
Université de Toulouse (UT)-Université Toulouse Capitole (UT Capitole)
Université de Toulouse (UT)
Université Toulouse - Jean Jaurès (UT2J)-Université Toulouse 1 Capitole (UT1)
Université Fédérale Toulouse Midi-Pyrénées-Université Fédérale Toulouse Midi-Pyrénées-Centre National de la Recherche Scientifique (CNRS)-Université Toulouse III - Paul Sabatier (UT3)
Université Fédérale Toulouse Midi-Pyrénées-Institut National des Sciences Appliquées - Toulouse (INSA Toulouse)
Institut National des Sciences Appliquées (INSA)-Institut National des Sciences Appliquées (INSA)-Institut National Polytechnique (Toulouse) (Toulouse INP)
Université Fédérale Toulouse Midi-Pyrénées-Université Toulouse - Jean Jaurès (UT2J)-Université Toulouse 1 Capitole (UT1)
Université Fédérale Toulouse Midi-Pyrénées
Source :
Proceedings of the 10th International Wireless Communications & Mobile Computing Conference (IWCMC), Traffic Analysis for Network Security (TRAC Workshop)-10th International Wireless Communications & Mobile Computing Conference (IWCMC)., Traffic Analysis for Network Security (TRAC Workshop)-10th International Wireless Communications & Mobile Computing Conference (IWCMC)., Aug 2014, Nicosia, Cyprus. 6p, IWCMC
Publication Year :
2014
Publisher :
HAL CCSD, 2014.

Abstract

6 pages; International audience; Traditional Network Intrusion Detection Systems (NIDSs) rely on either specialized signatures of previously seen attacks, or on expensive and difficult to produce labeled traffic datasets for profiling and training. Both approaches share a common downside: they require the knowledge provided by an external agent, either in terms of signatures or as normal-operation profiles. In this paper we describe UNIDS, an Unsupervised NIDS capable of detecting 0-day attacks, i.e., network attacks for which no signature is yet available, without using any kind of signatures, labeled traffic, or training. UNIDS uses a novel unsupervised outliers detection approach based on Sub-Space Clustering and Multiple Evidence Accumulation techniques to pin-point different kinds of network intrusions and attacks such as DoS/DDoS, probing attacks, propagation of worms, buffer overflows, illegal access to network resources, etc. In this paper we make the strong point that the de-facto approach for NIDS, namely the application of rule-based detection techniques, can be highly harmful for the protected network in case of 0-day attacks. In contrast, we show how UNIDS can work as a complementary system to current NIDS to detect the occurrence of previously unseen attacks. For doing so, we compare the performance of a standard rule-based NIDS against UNIDS to detect 0-day attacks in the well-known KDD99 dataset. In addition, we also compare the performance of UNIDS against other popular unsupervised detection techniques to detect attacks in traces collected at two operation networks.

Details

Language :
English
Database :
OpenAIRE
Journal :
Proceedings of the 10th International Wireless Communications & Mobile Computing Conference (IWCMC), Traffic Analysis for Network Security (TRAC Workshop)-10th International Wireless Communications & Mobile Computing Conference (IWCMC)., Traffic Analysis for Network Security (TRAC Workshop)-10th International Wireless Communications & Mobile Computing Conference (IWCMC)., Aug 2014, Nicosia, Cyprus. 6p, IWCMC
Accession number :
edsair.doi.dedup.....66e58089881770c629387b9722fbf625