Dissertation/ Thesis
A nonparametric density estimation approach to network intrusion detection
| Title: | A nonparametric density estimation approach to network intrusion detection |
|---|---|
| Authors: | Chow, Calvin |
| Publication Year: | 2001 |
| Collection: | The Hong Kong University of Science and Technology: HKUST Institutional Repository |
| Subject Terms: | Computer networks -- Security measures, Computer security, Computer networks -- Security measures -- Statistical methods, Computer security -- Statistical methods |
| Description: | Network intrusion detection has emerged as one of the ways to enforce computer security in recent years. It is the problem of detecting intrusive activities by using network data as the source. The commonest way is to hand-code the attack signatures into rules for detection. This approach is slow and expensive. Consequently, other techniques have been proposed to tackle the problem. Many of these techniques have to use both normal and intrusion data to build their classifiers. In practice, however, intrusion data are usually limited in quantity for model training. Therefore, we propose to solve the network intrusion detection problem by using a novelty detection approach. In particular, the probabilistic neural network (PNN) model based on the use of Parzen windows for nonparametric density estimation is used. Our method can build an intrusion detection system using only normal network traffic records. We have tested our system on the dataset used in the KDD Cup 1999 contest. Results show that our system performs favorably when compared to the winning system of the contest. The winning system, which is based on an ensemble of decision trees with bagged boosting, uses many intrusion records and much more normal data records for classifier training. This shows that our model is promising for solving the network intrusion problem. Besides, a speedup scheme for our model is presented. Moreover, we propose a service-based PNN model which is based on the detection of individual network service traffic. Experimental results for this model are also presented. |
| Document Type: | thesis |
| Language: | English |
| Availability: | http://repository.hkust.edu.hk/ir/Record/1783.1-5724 https://repository.hkust.edu.hk/ir/bitstream/1783.1-5724/1/b712118.pdf |
| Accession Number: | edsbas.F9A35D4 |
| Database: | BASE |
| FullText | Text: Availability: 0 CustomLinks: – Url: http://repository.hkust.edu.hk/ir/Record/1783.1-5724# Name: EDS - BASE (ns324271) Category: fullText Text: View record from BASE |
|---|---|
| Header | DbId: edsbas DbLabel: BASE An: edsbas.F9A35D4 RelevancyScore: 681 AccessLevel: 3 PubType: Dissertation/ Thesis PubTypeId: dissertation PreciseRelevancyScore: 681.354370117188 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: A nonparametric density estimation approach to network intrusion detection – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Chow%2C+Calvin%22">Chow, Calvin</searchLink> – Name: DatePubCY Label: Publication Year Group: Date Data: 2001 – Name: Subset Label: Collection Group: HoldingsInfo Data: The Hong Kong University of Science and Technology: HKUST Institutional Repository – Name: Subject Label: Subject Terms Group: Su Data: <searchLink fieldCode="DE" term="%22Computer+networks+--+Security+measures%22">Computer networks -- Security measures</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+networks+--+Security+measures+--+Statistical+methods%22">Computer networks -- Security measures -- Statistical methods</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+--+Statistical+methods%22">Computer security -- Statistical methods</searchLink> – Name: Abstract Label: Description Group: Ab Data: Network intrusion detection has emerged as one of the ways to enforce computer security in recent years. It is the problem of detecting intrusive activities by using network data as the source. The commonest way is to hand-code the attack signatures into rules for detection. This approach is slow and expensive. Consequently, other techniques have been proposed to tackle the problem. Many of these techniques have to use both normal and intrusion data to build their classifiers. In practice, however, intrusion data are usually limited in quantity for model training. Therefore, we propose to solve the network intrusion detection problem by using a novelty detection approach. In particular, the probabilistic neural network (PNN) model based on the use of Parzen windows for nonparametric density estimation is used. Our method can build an intrusion detection system using only normal network traffic records. We have tested our system on the dataset used in the KDD Cup 1999 contest. Results show that our system performs favorably when compared to the winning system of the contest. The winning system, which is based on an ensemble of decision trees with bagged boosting, uses many intrusion records and much more normal data records for classifier training. This shows that our model is promising for solving the network intrusion problem. Besides, a speedup scheme for our model is presented. Moreover, we propose a service-based PNN model which is based on the detection of individual network service traffic. Experimental results for this model are also presented. – Name: TypeDocument Label: Document Type Group: TypDoc Data: thesis – Name: Language Label: Language Group: Lang Data: English – Name: URL Label: Availability Group: URL Data: http://repository.hkust.edu.hk/ir/Record/1783.1-5724<br />https://repository.hkust.edu.hk/ir/bitstream/1783.1-5724/1/b712118.pdf – Name: AN Label: Accession Number Group: ID Data: edsbas.F9A35D4 |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edsbas&AN=edsbas.F9A35D4 |
| RecordInfo | BibRecord: BibEntity: Languages: – Text: English Subjects: – SubjectFull: Computer networks -- Security measures Type: general – SubjectFull: Computer security Type: general – SubjectFull: Computer networks -- Security measures -- Statistical methods Type: general – SubjectFull: Computer security -- Statistical methods Type: general Titles: – TitleFull: A nonparametric density estimation approach to network intrusion detection Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Chow, Calvin IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 01 Type: published Y: 2001 Identifiers: – Type: issn-locals Value: edsbas |
| ResultId | 1 |