Dissertation/ Thesis

A nonparametric density estimation approach to network intrusion detection

Bibliographic Details
Title: A nonparametric density estimation approach to network intrusion detection
Authors: Chow, Calvin
Publication Year: 2001
Collection: The Hong Kong University of Science and Technology: HKUST Institutional Repository
Subject Terms: Computer networks -- Security measures, Computer security, Computer networks -- Security measures -- Statistical methods, Computer security -- Statistical methods
Description: Network intrusion detection has emerged as one of the ways to enforce computer security in recent years. It is the problem of detecting intrusive activities by using network data as the source. The commonest way is to hand-code the attack signatures into rules for detection. This approach is slow and expensive. Consequently, other techniques have been proposed to tackle the problem. Many of these techniques have to use both normal and intrusion data to build their classifiers. In practice, however, intrusion data are usually limited in quantity for model training. Therefore, we propose to solve the network intrusion detection problem by using a novelty detection approach. In particular, the probabilistic neural network (PNN) model based on the use of Parzen windows for nonparametric density estimation is used. Our method can build an intrusion detection system using only normal network traffic records. We have tested our system on the dataset used in the KDD Cup 1999 contest. Results show that our system performs favorably when compared to the winning system of the contest. The winning system, which is based on an ensemble of decision trees with bagged boosting, uses many intrusion records and much more normal data records for classifier training. This shows that our model is promising for solving the network intrusion problem. Besides, a speedup scheme for our model is presented. Moreover, we propose a service-based PNN model which is based on the detection of individual network service traffic. Experimental results for this model are also presented.
Document Type: thesis
Language: English
Availability: http://repository.hkust.edu.hk/ir/Record/1783.1-5724
https://repository.hkust.edu.hk/ir/bitstream/1783.1-5724/1/b712118.pdf
Accession Number: edsbas.F9A35D4
Database: BASE
FullText Text:
  Availability: 0
CustomLinks:
  – Url: http://repository.hkust.edu.hk/ir/Record/1783.1-5724#
    Name: EDS - BASE (ns324271)
    Category: fullText
    Text: View record from BASE
Header DbId: edsbas
DbLabel: BASE
An: edsbas.F9A35D4
RelevancyScore: 681
AccessLevel: 3
PubType: Dissertation/ Thesis
PubTypeId: dissertation
PreciseRelevancyScore: 681.354370117188
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: A nonparametric density estimation approach to network intrusion detection
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Chow%2C+Calvin%22">Chow, Calvin</searchLink>
– Name: DatePubCY
  Label: Publication Year
  Group: Date
  Data: 2001
– Name: Subset
  Label: Collection
  Group: HoldingsInfo
  Data: The Hong Kong University of Science and Technology: HKUST Institutional Repository
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+networks+--+Security+measures%22">Computer networks -- Security measures</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+networks+--+Security+measures+--+Statistical+methods%22">Computer networks -- Security measures -- Statistical methods</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+--+Statistical+methods%22">Computer security -- Statistical methods</searchLink>
– Name: Abstract
  Label: Description
  Group: Ab
  Data: Network intrusion detection has emerged as one of the ways to enforce computer security in recent years. It is the problem of detecting intrusive activities by using network data as the source. The commonest way is to hand-code the attack signatures into rules for detection. This approach is slow and expensive. Consequently, other techniques have been proposed to tackle the problem. Many of these techniques have to use both normal and intrusion data to build their classifiers. In practice, however, intrusion data are usually limited in quantity for model training. Therefore, we propose to solve the network intrusion detection problem by using a novelty detection approach. In particular, the probabilistic neural network (PNN) model based on the use of Parzen windows for nonparametric density estimation is used. Our method can build an intrusion detection system using only normal network traffic records. We have tested our system on the dataset used in the KDD Cup 1999 contest. Results show that our system performs favorably when compared to the winning system of the contest. The winning system, which is based on an ensemble of decision trees with bagged boosting, uses many intrusion records and much more normal data records for classifier training. This shows that our model is promising for solving the network intrusion problem. Besides, a speedup scheme for our model is presented. Moreover, we propose a service-based PNN model which is based on the detection of individual network service traffic. Experimental results for this model are also presented.
– Name: TypeDocument
  Label: Document Type
  Group: TypDoc
  Data: thesis
– Name: Language
  Label: Language
  Group: Lang
  Data: English
– Name: URL
  Label: Availability
  Group: URL
  Data: http://repository.hkust.edu.hk/ir/Record/1783.1-5724<br />https://repository.hkust.edu.hk/ir/bitstream/1783.1-5724/1/b712118.pdf
– Name: AN
  Label: Accession Number
  Group: ID
  Data: edsbas.F9A35D4
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edsbas&AN=edsbas.F9A35D4
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Text: English
    Subjects:
      – SubjectFull: Computer networks -- Security measures
        Type: general
      – SubjectFull: Computer security
        Type: general
      – SubjectFull: Computer networks -- Security measures -- Statistical methods
        Type: general
      – SubjectFull: Computer security -- Statistical methods
        Type: general
    Titles:
      – TitleFull: A nonparametric density estimation approach to network intrusion detection
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Chow, Calvin
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Type: published
              Y: 2001
          Identifiers:
            – Type: issn-locals
              Value: edsbas
ResultId 1