Application of Case-Based Reasoning to Multi-Sensor Network Intrusion Detection
نویسندگان
چکیده
An intrusion detection system (IDS) is generally limited by having a single detection model and a single information source for detecting attacks. Multi-sensor (or meta) intrusion detection addresses this problem by combining results of multiple IDSs and providing global decisions. Nearly all current meta-IDSs are either statistics-based or logical rule-based and typically require substantial human involvement for setup. This paper reports two experiments that employ a case-based reasoning (CBR) approach, one using the wellknown 1998 DARPA datasets, which contain a variety of different types of attacks, and one using the 2000 DARPA datasets, which contain distributed denial of service (DDOS) attacks. A critical issue with meta-IDS is alert correlation: determining when alerts from the various sensors are generated by the same attack. The first experiment uses explicit alert correlation based on session information contained in the alerts. In addition, it avoids human involvement in setup by employing data mining techniques to generate the case library automatically from training data. The results show that the CBR approach is very effective in distinguishing false alerts from real attacks, and in many of the latter cases can correctly identify the type of attack. The second experiment applies CBR to achieve a kind of implicit alert correlation. Explicit correlation is not possible here, since DDOS attacks span multiple network sessions. Here again the approach has proven effective. For the second experiment the case library is derived directly from the training data without data mining techniques. Key-Words: Case-Based Reasoning, Data-Mining, Intrusion Detection, Alert Correlation
منابع مشابه
MHIDCA: Multi Level Hybrid Intrusion Detection and Continuous Authentication for MANET Security
Mobile ad-hoc networks have attracted a great deal of attentions over the past few years. Considering their applications, the security issue has a great significance in them. Security scheme utilization that includes prevention and detection has the worth of consideration. In this paper, a method is presented that includes a multi-level security scheme to identify intrusion by sensors and authe...
متن کاملA Lightweight Intrusion Detection System Based on Specifications to Improve Security in Wireless Sensor Networks
Due to the prevalence of Wireless Sensor Networks (WSNs) in the many mission-critical applications such as military areas, security has been considered as one of the essential parameters in Quality of Service (QoS), and Intrusion Detection System (IDS) is considered as a fundamental requirement for security in these networks. This paper presents a lightweight Intrusion Detection System to prote...
متن کاملSecuring Cluster-heads in Wireless Sensor Networks by a Hybrid Intrusion Detection System Based on Data Mining
Cluster-based Wireless Sensor Network (CWSN) is a kind of WSNs that because of avoiding long distance communications, preserve the energy of nodes and so is attractive for related applications. The criticality of most applications of WSNs and also their unattended nature, makes sensor nodes often susceptible to many types of attacks. Based on this fact, it is clear that cluster heads (CHs) are ...
متن کاملEvaluation of an Intrusion Detection System for Routing Attacks in Wireless Self-organised Networks
Wireless Sensor Networks (WSNs) arebecoming increasingly popular, and very useful in militaryapplications and environmental monitoring. However,security is a major challenge for WSNs because they areusually setup in unprotected environments. Our goal in thisstudy is to simulate an Intrusion Detection System (IDS)that monitors the WSN and report intrusions accurately andeffectively. We have thus...
متن کاملOutlier Detection in Wireless Sensor Networks Using Distributed Principal Component Analysis
Detecting anomalies is an important challenge for intrusion detection and fault diagnosis in wireless sensor networks (WSNs). To address the problem of outlier detection in wireless sensor networks, in this paper we present a PCA-based centralized approach and a DPCA-based distributed energy-efficient approach for detecting outliers in sensed data in a WSN. The outliers in sensed data can be ca...
متن کامل