A Nonparametric Multichart CUSUM Test for Rapid Intrusion Detection

نویسندگان

  • Alexander G. Tartakovsky
  • Boris L. Rozovskii
  • Khushboo Shah
چکیده

An efficient sequential nonparametric multichart (multichannel) CUSUM-type detection test for detecting changes in multichannel sensor systems is proposed. While there is a wide spectrum of applications where it is necessary to consider multichannel generalizations and general statistical models in change-point detection problems, the study in this paper is motivated by network security. Many kinds of intrusions in computer networks lead to abrupt changes in network traffic. These changes have to be detected as rapidly as possible while maintaining a false alarm rate at a low level. Computer intrusion detection encourages the development of a nonparametric multichannel change-point detection test that does not use exact legitimate (pre-change) and attack (post-change) traffic models. The proposed nonparametric detection procedure can be effectively applied to detect a wide variety of attacks such as external denial of service attacks, worm based attacks, port scanning, and insider man-in-the-middle attacks. Operating characteristics of the proposed multichannel CUSUM test are evaluated for real denial of service attacks using traces recently collected by CAIDA. The results of a comparison with a conventional singlechannel CUSUM algorithm show that the multichannel test has much better performance.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Application and Analyses of Cumulative Sum to Detect Highly Distributed Denial of Service Attacks using Different Attack Traffic Patterns

A different and simple scheme was proposed in [1] to detect highly Distributed Denial of Service attacks by monitoring the number of new source IP addresses. The scheme referred uses a recursive nonparametric change point detection method, called Cumulative Sum (CUSUM) that was presented in [2]. In this paper the main ideas from [1] are reviewed. Using different attack traffic patterns it was p...

متن کامل

Anomaly Detection Based on a Multi-class CUSUM Algorithm for WSN

Security is one of the most important research issues in wireless sensor networks (WSN) applications. Given that the single detection threshold of the cumulative sum (CUSUM) algorithm causes longer detection delays and a lower detection rate, a multi-class CUSUM algorithm is hereby proposed. Firstly a maximum and minimum thresholds, which sensor nodes are able to reach during sending packet, ar...

متن کامل

An Inner DoS/DDoS Attack Detection System

In this article, we proposed an inner intrusion detection system, named Cumulative-Sum-based Inner Intrusion Detection System (CSIIDS), which detects inner malicious behaviors, launched toward local servers/hosts by other local hosts. Detection is performed based on Cumulative Sum (CUSUM) algorithm. Experimental results show that CSIIDSs can carry out a higher security level for the protected n...

متن کامل

Robust and nonparametric detection of shifts in time series

A classical test for the detection of level shifts in such weakly dependent data is the CUSUM test, which compares the partial sum of the first m observations to the sum of all observations for each candidate change-point m, and maximizes this statistic with respect to m after some appropriate scaling. Asymptotical critical values for the CUSUM test can be calculated from tables of the Kolmogor...

متن کامل

Anomaly Detection Based on a Multi-class CUSUM Algorithm for WSN

Security is one of the most important research issues in wireless sensor networks (WSN) applications. Given that the single detection threshold of the cumulative sum (CUSUM) algorithm causes longer detection delays and a lower detection rate, a multi-class CUSUM algorithm is hereby proposed. Firstly a maximum and minimum thresholds, which sensor nodes are able to reach during sending packet, ar...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007