Abstract
In order to prevent the intrusion in network-based information systems effectively, it is necessary to detect the early sign in advance of intrusion. This sort of pre-alerting approach may be classified as an active prevention, since detecting the various forms of hackers’ intrusion trials to know the vulnerability of systems is not missed and early cross-checked. The existing network-based anomaly detection algorithms that cope with port-scanning and the network vulnerability scans have some weakness in slow scans and coordinated scans. Therefore, a new concept of pre-alerting algorithm is especially attractive to detect effectively the various forms of abnormal accesses for the trial of intrusion regardless of the intrusion methods. In this paper, we propose a session pattern anomaly detector (SPAD) which detects the abnormal service patterns by comparing them with the ordinary normal service patterns.
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Solar Designer: Designing and Attacking Port Scan Detection Tools. Phrack Magazine 8(53) (July 8, 1998)
Fyodor: The Art of Port Scanning. Phrack Magazine 7(51) (September 01, 1997)
Publication of Real-time Network Illegal Scanning Automatic Detection Tool (RTSD), http://www.certcc.or.kr/
Staniford, S., Hoagland, J.A., Mcalerney, J.M.: Practical Automated Detection of Stealthy Portscans, http://www.silicondefense.com/software/spice/index.htm
Hoagland, J.A., Staniford, S.: Viewing IDS alerts: Lessons from SnortSnarf. IEEE, Los Alamitos (2001)
McHugh, J.: Testing Intrusion Detection Systems: A Cririque of the 1998 and 1999 DARPA Intrusion Detection System Evaluations as Performed by Lincoln Laboratory. ACM Transactions on Information and System Security 3(4), 262–294 (2000)
Attack database, http://www.ll.mit.edu/IST/ideval/docs/docs_index.html
Off-Line Simulation Network, http://www.ll.mit.edu/IST/ideval/docs/docs_index.html
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2006 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Park, SJ., Park, YS., Choi, YR., Kang, S. (2006). SPAD: A Session Pattern Anomaly Detector for Pre-alerting Intrusions in Home Network. In: Gavrilova, M.L., et al. Computational Science and Its Applications - ICCSA 2006. ICCSA 2006. Lecture Notes in Computer Science, vol 3983. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11751632_47
Download citation
DOI: https://doi.org/10.1007/11751632_47
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-34077-5
Online ISBN: 978-3-540-34078-2
eBook Packages: Computer ScienceComputer Science (R0)