A New Intrusion Detection Method Based on Discriminant Analysis (Special Issue on High-speed Internet Technology and its Applications)
スポンサーリンク
概要
- 論文の詳細を見る
Many methods have been proposed to detect intrusions; for example, the pattern matching method on known intrusion patterns and the statistical approach to detecting deviation from normal activities. We investigated a new method for detecting intrusions based on the number of system calls during a user's network activity on a host machine. This method attempts to separate intrusions from normal activities by using discriminant analysis, a kind of multivariate analysis. We can detect intrusions by analyzing only 11 system calls occurring on a host machine by discriminant analysis with the Mahalanobis' distance, and can also tell whether an unknown sample is an intrusion. Our approach is a lightweight intrusion detection method, given that it requires only 11 system calls for analysis. Moreover, our approach does not require user profiles or a user activity database in order to detect intrusions. This paper explains our new method for the separation of intrusions and normal behavior by discriminant analysis, and describes the classification method by which to identify an unknown behavior.
- 社団法人電子情報通信学会の論文
- 2001-05-01
著者
-
Goto S
Waseda Univ. Tokyo Jpn
-
GOTO SHIGEKI
Waseda University
-
ASAKA Midori
Information-technology Promotion Agency, Japan.
-
ONABUTA Takefumi
Information-technology Promotion Agency, Japan.
-
INOUE Tadashi
Information-Technology Promotion Agency
-
OKAZAWA Shunji
Japan Research Institute
-
Onabuta Takefumi
Information-technology Promotion Agency
-
Asaka Midori
Information-technology Promotion Agency
関連論文
- An Improved Intrusion Detecting Method Based on Process Profiling(Special Issue on Selected Papers from SAINT 2002(The 2002 Symposium on Applications and the Internet))
- Public Information Server for Tracing Intruders in the Internet(Special Issue on Network Software)
- A New Intrusion Detection Method Based on Discriminant Analysis (Special Issue on High-speed Internet Technology and its Applications)
- Local Attack Detection and Intrusion Route Tracing (Special Issue on New Paradigms in Network Management)