Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

Intrusion detection

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 1 - 30 of 33

Full-Text Articles in Information Security

A Survey Of Privacy-Preserving Federated Learning For Intrusion Detection Systems, Thomas Bunko, Michael N. Johnstone, Wencheng Yang, Ben A. Scott May 2026

A Survey Of Privacy-Preserving Federated Learning For Intrusion Detection Systems, Thomas Bunko, Michael N. Johnstone, Wencheng Yang, Ben A. Scott

Research outputs 2022 to 2026

Intrusion detection systems (IDS) monitor and detect malicious activity and unauthorized access that may compromise systems. Traditional IDS approaches send data to a central server for analysis, raising privacy concerns as data owners lose control over security. Federated Learning (FL) offers a privacy-preserving alternative by allowing local devices to process their data and generate models without sharing raw data. These local models are aggregated centrally to form a comprehensive model with performance comparable to centralized systems. This paper reviews FL-based IDS research, and is the first review paper to focus on privacy-preserving techniques collectively known as privacy-preserving Federated Learning (PPFL) …


Application Identification With Pfsense, Snort, And Openappid In Academic Lab Networks, Minh-Khanh Vu Apr 2026

Application Identification With Pfsense, Snort, And Openappid In Academic Lab Networks, Minh-Khanh Vu

Journal of Cybersecurity Education, Research and Practice

This paper evaluates the practical capabilities and limitations of a widely used open-source network security stack—pfSense firewall, Snort Intrusion Detection System (IDS), and OpenAppID detectors—in academic cy- bersecurity laboratories and small-to-medium enterprise (SME)-like environments. In a controlled virtual testbed, we measure application-level and feature-level identifi- cation performance for major applications (Facebook, YouTube, Zoom) using the pfSense/Snort/OpenAppID configuration. The stack achieves 97% application-level identification accuracy for these applications in our lab dataset, drawing on a library of 3,374 OpenAppID detectors. However, our experiments reveal a substan- tial feature-level detection gap: specific functions such as Zoom file transfers and Facebook messaging can- …


Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker Mar 2026

Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker

Research outputs 2022 to 2026

As networks expand in size and complexity, coupled with an exponential increase in intrusions on network and IoT systems, this leads to traditional models failing to capture increasingly intricate correlations among network components accurately. Graph Convolution Networks (GCNs) have recently acquired prominence for their capacity to represent nodes, edges, or entire graphs by aggregating information from adjacent nodes. However, the correlations between nodes and their neighbours, as well as related edges, differ. Assigning higher weights to nodes and edges with high similarity improves model accuracy and expressiveness. In this paper, we propose the GCN-DQN model, which integrates GCN with a …


Enhancing Healthcare Security: Manifold-Aware Machine Learning For Robust Adversarial Attack Detection In Iomt Networks, Mohmmad Al-Fawa’Reh, Mohammed Kaosar Jan 2026

Enhancing Healthcare Security: Manifold-Aware Machine Learning For Robust Adversarial Attack Detection In Iomt Networks, Mohmmad Al-Fawa’Reh, Mohammed Kaosar

Research outputs 2022 to 2026

The widespread adoption of Internet of Medical Things (IoMT) devices and the increasing movement towards telehealth have revolutionized healthcare delivery but also introduced significant security challenges. Tiny Machine Learning (TinyML) models deployed on resource-constrained medical devices are vulnerable to adversarial attacks that can compromise patient data and device functionality, posing risks to patient safety. To address these critical security concerns, this paper proposes MARD (Manifold-Aware Robust Defense), a defense mechanism designed to enhance the robustness of TinyML models. MARD trains a compact student model by transferring knowledge from a teacher model that incorporates Graph-based Manifold Regularization (GMR) and Manifold Mixup …


Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias Jan 2026

Gem-Can: A Real-World Dataset Of Can-Bus Attack Scenarios On An Autonomous Vehicle For Intrusion-Detection Research, Mahsa Tavasoli, Abdolhossein Sarrafzadeh, Ali Karimoddini, Tienake Phuapaiboon, Milad Khaleghi, Daniel Tobias

Electrical & Computer Engineering Faculty Publications

This paper presents GEM-CAN, a labelled Controller Area Network (CAN) dataset captured from an autonomous GEM e6 platform under both normal operation and controlled cyber-attack conditions.

The dataset contains ∼143 K frames comprising (i) ∼ nominal autonomous operation (∼100k messages), (ii) DoS floods using arbitration ID 0 × 00000000 (∼41 K messages), and (iii) data-tampering injections that reuse legitimate IDs for brake and steering-lock (∼1.3 K messages). Each record includes timestamp, arbitration ID (11/29-bit), DLC, eight payload bytes, and a Normal/Attack label. A companion metadata file enumerates attack windows, PCAN bus-load traces, bitrate, and test conditions. Data were collected with …


Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan Oct 2024

Setc: A Vulnerability Telemetry Collection Framework, Ryan Holeman, John Hastings, Varghese Mathew Vaidyan

Research & Publications

As emerging software vulnerabilities continuously threaten enterprises and Internet services, there is a critical need for improved security research capabilities. This paper introduces the Security Exploit Telemetry Collection (SETC) framework - an automated framework to generate reproducible vulnerability exploit data at scale for robust defensive security research. SETC deploys configurable environments to execute and record rich telemetry of vulnerability exploits within isolated containers. Exploits, vulnerable services, monitoring tools, and logging pipelines are defined via modular JSON configurations and deployed on demand. Compared to current manual processes, SETC enables automated, customizable, and repeatable vulnerability testing to produce diverse security telemetry. This …


A Systemic Mapping Study On Intrusion Response Systems, Adel Rezapour, Mohammad Ghasemigol, Daniel Takabi Jan 2024

A Systemic Mapping Study On Intrusion Response Systems, Adel Rezapour, Mohammad Ghasemigol, Daniel Takabi

School of Cybersecurity Faculty Publications

With the increasing frequency and sophistication of network attacks, network administrators are facing tremendous challenges in making fast and optimum decisions during critical situations. The ability to effectively respond to intrusions requires solving a multi-objective decision-making problem. While several research studies have been conducted to address this issue, the development of a reliable and automated Intrusion Response System (IRS) remains unattainable. This paper provides a Systematic Mapping Study (SMS) for IRS, aiming to investigate the existing studies, their limitations, and future directions in this field. A novel semi-automated research methodology is developed to identify and summarize related works. The innovative …


Mitigating Cyber Espionage: A Network Security Strategy Using Notifications, Claire Headland Jan 2024

Mitigating Cyber Espionage: A Network Security Strategy Using Notifications, Claire Headland

Williams Honors College, Honors Research Projects

Network security and its mitigation of cyber espionage is paramount to the confidentiality, integrity, and availability of data within the intelligence field. With the advancing efficacy of social engineering to execute cyber espionage attacks, further measures and fail-safe mechanisms have become necessary. If a malicious actor successfully penetrates the network, suspending confidential data transmissions over the compromised network becomes crucial. However, connected users need a platform to receive security notifications and, therefore, need to know that their continued network use compromises more data. This project eliminates this by achieving two primary objectives: designing a multi- layered, hardened, and segmented network …


Ensemble Learning With Sleep Mode Management To Enhance Anomaly Detection In Iot Environment, Khawlah Harahsheh, Rami Al-Naimat, Malek Alzaqebah, Salam Shreem, Esraa Aldreabi, Chung-Hao Chen Jan 2024

Ensemble Learning With Sleep Mode Management To Enhance Anomaly Detection In Iot Environment, Khawlah Harahsheh, Rami Al-Naimat, Malek Alzaqebah, Salam Shreem, Esraa Aldreabi, Chung-Hao Chen

Electrical & Computer Engineering Faculty Publications

The rapid proliferation of Internet of Things (IoT) devices has underscored the critical need for energy-efficient cybersecurity measures. This presents the dual challenge of maintaining robust security while minimizing power consumption. Thus, this paper proposes enhancing the machine learning performance through Ensemble Techniques with Sleep Mode Management (ELSM) approach for IoT Intrusion Detection Systems (IDS). The main challenge lies in the high-power consumption attributed to continuous monitoring in traditional IDS setups. ELSM addresses this challenge by introducing a sophisticated sleep-awake mechanism, activating the IDS system only during anomaly detection events, effectively minimizing energy expenditure during periods of normal network operation. …


Self-Learning Algorithms For Intrusion Detection And Prevention Systems (Idps), Juan E. Nunez, Roger W. Tchegui Donfack, Rohit Rohit, Hayley Horn Mar 2023

Self-Learning Algorithms For Intrusion Detection And Prevention Systems (Idps), Juan E. Nunez, Roger W. Tchegui Donfack, Rohit Rohit, Hayley Horn

SMU Data Science Review

Today, there is an increased risk to data privacy and information security due to cyberattacks that compromise data reliability and accessibility. New machine learning models are needed to detect and prevent these cyberattacks. One application of these models is cybersecurity threat detection and prevention systems that can create a baseline of a network's traffic patterns to detect anomalies without needing pre-labeled data; thus, enabling the identification of abnormal network events as threats. This research explored algorithms that can help automate anomaly detection on an enterprise network using Canadian Institute for Cybersecurity data. This study demonstrates that Neural Networks with Bayesian …


Intrusion Detection Based On Bidirectional Long Short-Term Memory With Attention Mechanism, Yongjie Yang, Shanshan Tu, Raja Hashim Ali, Hisham Alasmary, Muhammad Waqas, Muhammad Nouman Amjad Jan 2023

Intrusion Detection Based On Bidirectional Long Short-Term Memory With Attention Mechanism, Yongjie Yang, Shanshan Tu, Raja Hashim Ali, Hisham Alasmary, Muhammad Waqas, Muhammad Nouman Amjad

Research outputs 2022 to 2026

With the recent developments in the Internet of Things (IoT), the amount of data collected has expanded tremendously, resulting in a higher demand for data storage, computational capacity, and real-time processing capabilities. Cloud computing has traditionally played an important role in establishing IoT. However, fog computing has recently emerged as a new field complementing cloud computing due to its enhanced mobility, location awareness, heterogeneity, scalability, low latency, and geographic distribution. However, IoT networks are vulnerable to unwanted assaults because of their open and shared nature. As a result, various fog computing-based security models that protect IoT networks have been developed. …


Malbot-Drl: Malware Botnet Detection Using Deep Reinforcement Learning In Iot Networks, Mohammad Al-Fawa'reh, Jumana Abu-Khalaf, Patryk Szewczyk, James J. Kang Jan 2023

Malbot-Drl: Malware Botnet Detection Using Deep Reinforcement Learning In Iot Networks, Mohammad Al-Fawa'reh, Jumana Abu-Khalaf, Patryk Szewczyk, James J. Kang

Research outputs 2022 to 2026

In the dynamic landscape of cyber threats, multi-stage malware botnets have surfaced as significant threats of concern. These sophisticated threats can exploit Internet of Things (IoT) devices to undertake an array of cyberattacks, ranging from basic infections to complex operations such as phishing, cryptojacking, and distributed denial of service (DDoS) attacks. Existing machine learning solutions are often constrained by their limited generalizability across various datasets and their inability to adapt to the mutable patterns of malware attacks in real world environments, a challenge known as model drift. This limitation highlights the pressing need for adaptive Intrusion Detection Systems (IDS), capable …


Camdec: Advancing Axis P1435-Le Video Camera Security Using Honeypot-Based Deception, Leslie F. Sikos, Craig Valli, Alexander E. Grojek, David J. Holmes, Samuel G. Wakeling, Warren Z. Cabral, Nickson M. Karie Jan 2023

Camdec: Advancing Axis P1435-Le Video Camera Security Using Honeypot-Based Deception, Leslie F. Sikos, Craig Valli, Alexander E. Grojek, David J. Holmes, Samuel G. Wakeling, Warren Z. Cabral, Nickson M. Karie

Research outputs 2022 to 2026

The explosion of online video streaming in recent years resulted in advanced services both in terms of efficiency and convenience. However, Internet-connected video cameras are prone to exploitation, leading to information security issues and data privacy concerns. The proliferation of video-capable Internet of Things devices and cloud-managed surveillance systems further extend these security issues and concerns. In this paper, a novel approach is proposed for video camera deception via honeypots, offering increased security measures compared to what is available on conventional Internet-enabled video cameras.


Federated Deep Learning For Cyber Security In The Internet Of Things: Concepts, Applications, And Experimental Analysis, Mohamed Amine Ferrag, Othmane Friha, Leandros Maglaras, Helge Janicke, Lei Shu Jan 2021

Federated Deep Learning For Cyber Security In The Internet Of Things: Concepts, Applications, And Experimental Analysis, Mohamed Amine Ferrag, Othmane Friha, Leandros Maglaras, Helge Janicke, Lei Shu

Research outputs 2014 to 2021

In this article, we present a comprehensive study with an experimental analysis of federated deep learning approaches for cyber security in the Internet of Things (IoT) applications. Specifically, we first provide a review of the federated learning-based security and privacy systems for several types of IoT applications, including, Industrial IoT, Edge Computing, Internet of Drones, Internet of Healthcare Things, Internet of Vehicles, etc. Second, the use of federated learning with blockchain and malware/intrusion detection systems for IoT applications is discussed. Then, we review the vulnerabilities in federated learning-based security and privacy systems. Finally, we provide an experimental analysis of federated …


Applications Of Machine Learning To Threat Intelligence, Intrusion Detection And Malware, Charity Barker Apr 2020

Applications Of Machine Learning To Threat Intelligence, Intrusion Detection And Malware, Charity Barker

Senior Honors Theses

Artificial Intelligence (AI) and Machine Learning (ML) are emerging technologies with applications to many fields. This paper is a survey of use cases of ML for threat intelligence, intrusion detection, and malware analysis and detection. Threat intelligence, especially attack attribution, can benefit from the use of ML classification. False positives from rule-based intrusion detection systems can be reduced with the use of ML models. Malware analysis and classification can be made easier by developing ML frameworks to distill similarities between the malicious programs. Adversarial machine learning will also be discussed, because while ML can be used to solve problems or …


A Dendritic Cell Algorithm Based Approach For Malicious Tcp Port Scanning Detection, Nuha Yousef Al Masalmeh Apr 2019

A Dendritic Cell Algorithm Based Approach For Malicious Tcp Port Scanning Detection, Nuha Yousef Al Masalmeh

Information Security Theses

The proliferation of cyber-attacks is accompanied by an urgent need to develop sophisticated detection tools. Some of these tools are based on algorithms inspired by the Human Immune System (HIS). The Dendritic Cell Algorithm (DCA) is one of such HIS inspired methods, which is based on the Danger theory model. In this thesis, two types of DCA algorithms are identified, namely the deterministic a classical DCA in order to improve the algorithm's applicability and performance to detect TCP port scanning. This algorithm consists of components based on the behavior of Human dendritic cells, which involves four categories of the input …


Bringing Defensive Artificial Intelligence Capabilities To Mobile Devices, Kevin Chong, Ahmed Ibrahim Jan 2018

Bringing Defensive Artificial Intelligence Capabilities To Mobile Devices, Kevin Chong, Ahmed Ibrahim

Australian Information Security Management Conference

Traditional firewalls are losing their effectiveness against new and evolving threats today. Artificial intelligence (AI) driven firewalls are gaining popularity due to their ability to defend against threats that are not fully known. However, a firewall can only protect devices in the same network it is deployed in, leaving mobile devices unprotected once they leave the network. To comprehensively protect a mobile device, capabilities of an AI-driven firewall can enhance the defensive capabilities of the device. This paper proposes porting AI technologies to mobile devices for defence against today’s ever-evolving threats. A defensive AI technique providing firewall-like capability is being …


Design And Evaluation Of Advanced Collusion Attacks On Collaborative Intrusion Detection Networks In Practice, Weizhi Meng, Xiapu Luo, Wenjuan Li, Yan Li Aug 2016

Design And Evaluation Of Advanced Collusion Attacks On Collaborative Intrusion Detection Networks In Practice, Weizhi Meng, Xiapu Luo, Wenjuan Li, Yan Li

Research Collection School Of Computing and Information Systems

To encourage collaboration among single intrusion detection systems (IDSs), collaborative intrusion detection networks (CIDNs) have been developed that enable different IDS nodes to communicate information with each other. This distributed network infrastructure aims to improve the detection performance of a single IDS, but may suffer from various insider attacks like collusion attacks, where several malicious nodes can collaborate to perform adversary actions. To defend against insider threats, challenge-based trust mechanisms have been proposed in the literature and proven to be robust against collusion attacks. However, we identify that such mechanisms depend heavily on an assumption of malicious nodes, which is …


A Hybrid Behaviour Recognition And Intrusion Detection Method For Mobile Devices, Ashley Woodiss-Field Jan 2016

A Hybrid Behaviour Recognition And Intrusion Detection Method For Mobile Devices, Ashley Woodiss-Field

Australian Information Security Management Conference

Behaviour-based authorisation is a technique that assesses the user of a device for authenticity by comparing their activities to previously established behaviour profiles. Passwords and other point of entry authorisation techniques are often inadequate for protecting mobile device security as they only provide an initial barrier to usage and do not operate continuously. Behaviour-based authorisation continuously assesses user authorisation, using the device owner’s profile for authentication. This research improves upon behaviour-based authorisation performance by applying a hybridised intrusion detection method. The constituent intrusion detection methods that were applied include context-awareness and self-correction. Performance of a behaviour-based authorisation method can be …


Optical Fiber Sensors In Physical Intrusion Detection Systems: A Review, Gary Andrew Allwood, Graham Wild, Steven Hinkley Jan 2016

Optical Fiber Sensors In Physical Intrusion Detection Systems: A Review, Gary Andrew Allwood, Graham Wild, Steven Hinkley

Research outputs 2014 to 2021

Fiber optic sensors have become a mainstream sensing technology within a large array of applications due to their inherent benefits. They are now used significantly in structural health monitoring, and are an essential solution for monitoring harsh environments. Since their first development over 30 years ago, they have also found promise in security applications. This paper reviews all of the optical fiber-based techniques used in physical intrusion detection systems. It details the different approaches used for sensing, interrogation, and networking, by research groups, attempting to secure both commercial and residential premises from physical security breaches. The advantages and the disadvantages …


Intensity Based Interrogation Of Optical Fibre Sensors For Industrial Automation And Intrusion Detection Systems, Gary Andrew Allwood Jan 2015

Intensity Based Interrogation Of Optical Fibre Sensors For Industrial Automation And Intrusion Detection Systems, Gary Andrew Allwood

Theses: Doctorates and Masters

In this study, the use of optical fibre sensors for intrusion detection and industrial automation systems has been demonstrated, with a particular focus on low cost, intensity-based, interrogation techniques. The use of optical fibre sensors for intrusion detection systems to secure residential, commercial, and industrial premises against potential security breaches has been extensively reviewed in this thesis. Fibre Bragg grating (FBG) sensing is one form of optical fibre sensing that has been underutilised in applications such as in-ground, in-fence, and window and door monitoring, and addressing that opportunity has been a major goal of this thesis. Both security and industrial …


Intelligent Network Intrusion Detection Using An Evolutionary Computation Approach, Samaneh Rastegari Jan 2015

Intelligent Network Intrusion Detection Using An Evolutionary Computation Approach, Samaneh Rastegari

Theses: Doctorates and Masters

With the enormous growth of users' reliance on the Internet, the need for secure and reliable computer networks also increases. Availability of effective automatic tools for carrying out different types of network attacks raises the need for effective intrusion detection systems.

Generally, a comprehensive defence mechanism consists of three phases, namely, preparation, detection and reaction. In the preparation phase, network administrators aim to find and fix security vulnerabilities (e.g., insecure protocol and vulnerable computer systems or firewalls), that can be exploited to launch attacks. Although the preparation phase increases the level of security in a network, this will never completely …


An Analysis Of Security Issues In Building Automation Systems, Matthew Peacock, Michael N. Johnstone Jan 2014

An Analysis Of Security Issues In Building Automation Systems, Matthew Peacock, Michael N. Johnstone

Australian Information Security Management Conference

The purpose of Building Automation Systems (BAS) is to centralise the management of a wide range of building services, through the use of integrated protocol and communication media. Through the use of IP-based communication and encapsulated protocols, BAS are increasingly being connected to corporate networks and also being remotely accessed for management purposes, both for convenience and emergency purposes. These protocols, however, were not designed with security as a primary requirement, thus the majority of systems operate with sub-standard or non-existent security implementations, relying on security through obscurity. Research has been undertaken into addressing the shortfalls of security implementations in …


Active Malware Analysis Using Stochastic Games, Simon Williamson, Pradeep Reddy Varakantham, Debin Gao, Chen Hui Ong Jun 2012

Active Malware Analysis Using Stochastic Games, Simon Williamson, Pradeep Reddy Varakantham, Debin Gao, Chen Hui Ong

Research Collection School Of Computing and Information Systems

Cyber security is increasingly important for defending computer systems from loss of privacy or unauthorised use. One important aspect is threat analysis - how does an attacker infiltrate a system and what do they want once they are inside. This paper considers the problem of Active Malware Analysis, where we learn about the human or software intruder by actively interacting with it with the goal of learning about its behaviours and intentions, whilst at the same time that intruder may be trying to avoid detection or showing those behaviours and intentions. This game-theoretic active learning is then used to obtain …


On Detection Of Erratic Arguments, Jin Han, Qiang Yan, Robert H. Deng, Debin Gao Sep 2011

On Detection Of Erratic Arguments, Jin Han, Qiang Yan, Robert H. Deng, Debin Gao

Research Collection School Of Computing and Information Systems

Due to the erratic nature, the value of a function argument in one normal program execution could become illegal in another normal execution context. Attacks utilizing such erratic arguments are able to evade detections as fine-grained context information is unavailable in many existing detection schemes. In order to obtain such fine-grained context information, a precise model on the internal program states has to be built, which is impractical especially monitoring a closed source program alone. In this paper, we propose an intrusion detection scheme which builds on two diverse programs providing semantically-close functionality. Our model learns underlying semantic correlation of …


Gap Analysis Of Intrusion Detection In Smart Grids, Nishchal Kush, Ernest Foo, Ejaz Ahmed, Irfan Ahmed, Andrew Clark Aug 2011

Gap Analysis Of Intrusion Detection In Smart Grids, Nishchal Kush, Ernest Foo, Ejaz Ahmed, Irfan Ahmed, Andrew Clark

International Cyber Resilience conference

Given the recent emergence of the smart grid and smart grid related technologies, their security is a prime concern. Intrusion detection provides a second line of defence. However, conventional intrusion detection systems (IDSs) are unable to adequately address the unique requirements of the smart grid. This paper presents a gap analysis of contemporary IDSs from a smart grid perspective. This paper highlights the lack of adequate intrusion detection within the smart grid and discusses the limitations of current IDSs approaches. The gap analysis identifies current IDSs as being unsuited to smart grid application without significant changes to address smart grid …


Mahalanobis Distance Map Approach For Anomaly Detection, Aruna Jamdagnil, Zhiyuan Tan, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu Nov 2010

Mahalanobis Distance Map Approach For Anomaly Detection, Aruna Jamdagnil, Zhiyuan Tan, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu

Australian Information Security Management Conference

Web servers and web-based applications are commonly used as attack targets. The main issues are how to prevent unauthorised access and to protect web servers from the attack. Intrusion Detection Systems (IDSs) are widely used security tools to detect cyber-attacks and malicious activities in computer systems and networks. In this paper, we focus on the detection of various web-based attacks using Geometrical Structure Anomaly Detection (GSAD) model and we also propose a novel algorithm for the selection of most discriminating features to improve the computational complexity of payload-based GSAD model. Linear Discriminant method (LDA) is used for the feature reduction …


Beyond Output Voting: Detecting Compromised Replicas Using Hmm-Based Behavioral Distance, Debin Gao, Michael K. Reiter, Dawn Song Apr 2009

Beyond Output Voting: Detecting Compromised Replicas Using Hmm-Based Behavioral Distance, Debin Gao, Michael K. Reiter, Dawn Song

Research Collection School Of Computing and Information Systems

Many host-based anomaly detection techniques have been proposed to detect code-injection attacks on servers. The vast majority, however, are susceptible to "mimicry" attacks in which the injected code masquerades as the original server software, including returning the correct service responses, while conducting its attack. "Behavioral distance," by which two diverse replicas processing the same inputs are continually monitored to detect divergence in their low-level (system-call) behaviors and hence potentially the compromise of one of them, has been proposed for detecting mimicry attacks. In this paper, we present a novel approach to behavioral distance measurement using a new type of hidden …


Heuristics For Improved Enterprise Intrusion Detection, James J. Treinen Jan 2009

Heuristics For Improved Enterprise Intrusion Detection, James J. Treinen

Electronic Theses and Dissertations

One of the greatest challenges facing network operators today is the identification of malicious activity on their networks. The current approach is to deploy a set of intrusion detection sensors (IDSs) in various locations throughout the network and on strategic hosts. Unfortunately, the available intrusion detection technologies generate an overwhelming volume of false alarms, making the task of identifying genuine attacks nearly impossible. This problem is very difficult to solve even in networks of nominal size. The task of uncovering attacks in enterprise class networks quickly becomes unmanageable.

Research on improving intrusion detection sensors is ongoing, but given the nature …


Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew Jan 2008

Can Intrusion Detection Implementation Be Adapted To End-User Capabilities?, Patricia A. Williams, Renji J. Mathew

Australian Information Security Management Conference

In an environment where technical solutions for securing networked systems are commonplace, there still exist problems in implementation of such solutions for home and small business users. One component of this protection is the use of intrusion detection systems. Intrusion detection monitors network traffic for suspicious activity, performs access blocking and alerts the system administrator or user of potential attacks. This paper reviews the basic function of intrusion detection systems and maps them to an existing end-user capability framework. Using this framework, implementation guidance and systematic improvement in implementation of this security measure are defined.