Download Network Anomaly Detection : Methods, Systems and Tools

Survey
yes no Was this document useful for you?
   Thank you for your participation!

* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project

Document related concepts

Cluster analysis wikipedia , lookup

Transcript
39
[159]
[160]
[161]
[162]
[163]
[164]
[165]
[166]
[167]
[168]
[169]
[170]
[171]
[172]
[173]
[174]
difference learning: Principles, models and case studies,” Applied Soft Computing, vol. 10, no. 3, pp. 859–867, 2010.
A. Prayote, “Knowledge Based Anomaly Detection,” Ph.D.
dissertation, School of Computer Science and Egineering, The
University of New South Wales, November 2007.
K. Ilgun, R. A. Kemmerer, and P. A. Porras, “State transition
analysis: A rule-based intrusion detection approach,” IEEE
Transactions on Software Engineering, vol. 21, no. 3, pp. 181–
199, 1995.
D. E. Denning and P. G. Neumann, “Requirements and model
for IDES a real-time intrusion detection system,” Computer Science Laboratory, SRI International, USA, Tech. Rep.
83F83-01-00, 1985.
D. Anderson, T. F. Lunt, H. Javitz, A. Tamaru, and A. Valdes,
“Detecting unusual program behaviour using the statistical
component of the next-generation intrusion detection expert
system (NIDES),” Computer Science Laboratory, SRI International, USA, Tech. Rep. SRIO-CSL-95-06, 1995.
N. G. Duffield, P. Haffner, B. Krishnamurthy, and H. Ringberg,
“Rule-Based Anomaly Detection on IP Flows,” in Proc. of
the 28th IEEE International Conference on Computer Communications, Joint Conference of the IEEE Computer and
Communications Societies.
Rio de Janeiro, Brazil: IEEE
press, 2009, pp. 424–432.
R. E. Schapire, “A brief introduction to boosting,” in Proc.
of the 16th International Joint Conference on Artificial Intelligence, Morgan Kaufmann, 1999, pp. 1401–1406.
A. Prayote and P. Compton, “Detecting anomalies and intruders,” AI 2006: Advances in Artificial Intelligence, pp. 1084–
1088, 2006.
G. Edwards, B. Kang, P. Preston, and P. Compton, “Prudent
expert systems with credentials: Managing the expertise of
decision support systems,” International journal of biomedical
computing, vol. 40, no. 2, pp. 125–132, 1995.
W. Scheirer and M. C. Chuah, “Syntax vs. semantics : competing approaches to dynamic network intrusion detection,”
International Journal Securrity and Networks, vol. 3, no. 1,
pp. 24–35, December 2008.
P. Naldurg, K. Sen, and P. Thati, “A Temporal Logic Based
Framework for Intrusion Detection,” in Proc. of the 24th IFIP
WG 6.1 International Conference on Formal Techniques for
Networked and Distributed Systems, 2004, pp. 359–376.
J. M. Estevez-Tapiador, P. Garcya-Teodoro, and J. E. DyazVerdejo, “Stochastic protocol modeling for anomaly based
network intrusion detection,” in Proc. of the 1st International
Workshop on Information Assurance. IEEE CS, 2003, pp.
3–12.
A. Shabtai, U. Kanonov, and Y. Elovici, “Intrusion detection
for mobile devices using the knowledge-based, temporal abstraction method,” Journal of System Software, vol. 83, no. 8,
pp. 1524–1537, August 2010.
S. S. Hung and D. S. M. Liu, “A user-oriented ontologybased approach for network intrusion detection,” Computer
Standards & Interfaces, vol. 30, no. 1-2, pp. 78–88, January
2008.
R. Polikar, “Ensemble based systems in decision making,”
IEEE Circuits System Magazine, vol. 6, no. 3, pp. 21–45, 2006.
A. Borji, “Combining heterogeneous classifiers for network
intrusion detection,” in Proc. of the 12th Asian Computing
Science Conference on Advances in Computer Science: Computer and Network Security. Springer, 2007, pp. 254–260.
G. Giacinto, R. Perdisci, M. D. Rio, and F. Roli, “Intrusion
detection in computer networks by a modular ensemble of oneclass classifiers,” Information Fusion, vol. 9, no. 1, pp. 69–82,
January 2008.
[175] L. Rokach, “Ensemble-based classifiers,” Artificial Intelligence
Review, vol. 33, no. 1-2, pp. 1–39, February 2010.
[176] K. Noto, C. Brodley, and D. Slonim, “Anomaly Detection
Using an Ensemble of Feature Models,” in Proc. of the IEEE
International Conference on Data Mining. USA: IEEE CS,
2010, pp. 953–958.
[177] P. M. Mafra, V. Moll, J. D. S. Fraga, and A. O. Santin,
“Octopus-IIDS: An Anomaly Based Intelligent Intrusion Detection System,” in Proc. of the IEEE Symposium on Computers and Communications. USA: IEEE CS, 2010, pp. 405–410.
[178] S. Chebrolu, A. Abraham, and J. P. Thomas, “Feature deduction and ensemble design of intrusion detection systems,”
Computers & Security, vol. 24, no. 4, pp. 295–307, 2005.
[179] L. Breiman, J. Friedman, R. Olshen, and C. Stone, Classification and Regression Trees. Monterey, CA: Wadsworth and
Brooks, 1984.
[180] R. Perdisci, G. Gu, and W. Lee, “Using an Ensemble of OneClass SVM Classifiers to Harden Payload-based Anomaly Detection Systems,” in Proc. of the 6th International Conference
on Data Mining. USA: IEEE CS, 2006, pp. 488–498.
[181] G. Folino, C. Pizzuti, and G. Spezzano, “An ensemble-based
evolutionary framework for coping with distributed intrusion
detection,” Genetic Programming and Evolvable Machines,
vol. 11, no. 2, pp. 131–146, June 2010.
[182] M. Rehak, M. Pechoucek, P. Celeda, J. Novotny, and P. Minarik, “CAMNEP: Agent-based Network Intrusion Detection
System,” in Proc. of the 7th International Joint Conference on
Autonomous Agents and Multiagent Systems: Industrial Track.
Richland, SC: IFAAMS, 2008, pp. 133–136.
[183] R. Perdisci, D. Ariu, P. Fogla, G. Giacinto, and W. Lee,
“McPAD: A multiple classifier system for accurate payloadbased anomaly detection,” Computer Networks, vol. 53, no. 6,
pp. 864–881, April 2009.
[184] W. Khreich, E. Granger, A. Miri, and R. Sabourin, “Adaptive
ROC-based ensembles of HMMs applied to anomaly detection,” Pattern Recognition, vol. 45, no. 1, pp. 208–230, January
2012.
[185] G. Giacinto, F. Roli, and L. Didaci, “Fusion of multiple classifiers for intrusion detection in computer networks,” Pattern
Recognition Letters, vol. 24, no. 12, pp. 1795–1803, August
2003.
[186] J. Shifflet, “A Technique Independent Fusion Model For
Network Intrusion Detection,” in Proc. of the Midstates Conference on Undergraduate Research in Computer Science and
Mathematics, vol. 3, 2005, pp. 13–19.
[187] D. Parikh and T. Chen, “Data Fusion and Cost Minimization
for Intrusion Detection,” IEEE Transactions on Information
Forensics and Security, vol. 3, no. 3, pp. 381–389, 2008.
[188] L. Zhi-dong, Y. Wu, W. Wei, and M. Da-peng, “Decisionlevel fusion model of multi-source intrusion detection alerts,”
Journal on Communications, vol. 32, no. 5, pp. 121–128, 2011.
[189] R. Yan and C. Shao, “Hierarchical Method for Anomaly
Detection and Attack Identification in High-speed Network,”
Information Technology Journal, vol. 11, no. 9, pp. 1243–
1250, 2012.
[190] V. Chatzigiannakis, G. Androulidakis, K. Pelechrinis, S. Papavassiliou, and V. Maglaris, “Data fusion algorithms for
network anomaly detection: classification and evaluation,” in
Proc. of the 3rd International Conference on Networking and
Services. Greece: IEEE CS, 2007, pp. 50–57.
[191] W. Gong, W. Fu, and L. Cai, “A Neural Network Based
Intrusion Detection Data Fusion Model,” in Proc. of the 3rd
International Joint Conference on Computational Science and
Optimization - Volume 02. USA: IEEE CS, 2010, pp. 410–
414.