loading...
Performance Evaluation of a Multi-Stage Network Event Detection Scheme for Decreasing the False-Positive Rate for a Large Number of Simultaneous, Unknown Events
Sainte-Luce, Martinique, France April 22-April 28
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ICN.2007.71Sixth International Conference on Net ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Tutomu Murase, NEC Corporation, Japan
Hiroki Fujiwara, Okayama University, Japan
Yukinobu Fukushima, Okayama University, Japan
Masayoshi Kobayashi, NEC Corporation, Japan
Tokumi Yokohira, Okayama University, Japan
Change-point detection schemes are a promising approach for detecting network anomalies, such as attacks and epidemics by unknown viruses and worms. They detect those events as change-points. However, they generally also detect false-positive change-points, those caused by other events such as hardware trouble. A scheme is needed that only detects true-positive change-points, caused by attacks and epidemics. True-positive change-points tend to occur simultaneously in very large numbers, while false-positive change-points tend to occur sporadically. We can exclude false-positive change-points by excluding change-points that occur sporadically, based on information gathered from the entire network. In this paper, we propose a multi-stage network event detection scheme that aggregates change-point information from distributed IDSs (Intrusion Detection Systems) and detects the true-positive change-points. Simulation results show that, compared to a scheme using only one IDS, our method always yields a smaller false-positive rate under the constraint that the detection rate of the true-positive change-points must exceed 0.99.
Index Terms:
Virus, Worm, Multi-Stage Network Anomaly Detection, Change-Point Detection, Large-Scale Simultaneous Event
Citation:
Tutomu Murase, Hiroki Fujiwara, Yukinobu Fukushima, Masayoshi Kobayashi, Tokumi Yokohira, "Performance Evaluation of a Multi-Stage Network Event Detection Scheme for Decreasing the False-Positive Rate for a Large Number of Simultaneous, Unknown Events," icn, pp.97, Sixth International Conference on Networking (ICN'07), 2007
Usage of this product signifies your acceptance of the Terms of Use.