Skip to main navigation Skip to search Skip to main content

Towards the scalable implementation of a user level anomaly detection system

  • SUNY Buffalo
  • Air Force Research Laboratory

Research output: Contribution to conferencePaperpeer-review

12 Scopus citations

Abstract

Traditional intrusion detection systems can be broadly classified as misuse and anomaly detectors. Misuse detectors attempt detection by matching the current system/user activity against known signatures and patterns. As opposed to this, anomaly detection works by developing a reference graph and comparing the ongoing activity against it. Any significant deviation is flagged as an intrusion. Anomaly detection is more promising because of its potential to detect unseen types of attacks. However, both techniques have conventionally relied on audit trails sampled deep inside the system via probes and the sheer size of the data allows only after-the-fact and off line detection. In recent past, there have been efforts to capture the semantics of system activity for more rapid detection and this can typically be done at levels closer to the user. In our earlier works related to this effort, we presented a scheme and a reasoning framework to detect intrusions based on the encapsulated user intent. This paper addresses the scalability and implementation aspects of the system by introducing concepts such as workspaces and meta-operations. Although this security system is a general anomaly detection system, it is amenable to operator fault recovery. While encryption provides secure communication channels, it leaves the end points exposed. Our security system has the additional capability of handling insider attacks relevant in this context.

Original languageEnglish
Pages1503-1508
Number of pages6
StatePublished - 2002
Event2002 MILCOM Proceedings; Global Information GRID - Enabling Transformation Through 21st Century Communications - Anaheim, CA, United States
Duration: Oct 7 2002Oct 10 2002

Conference

Conference2002 MILCOM Proceedings; Global Information GRID - Enabling Transformation Through 21st Century Communications
Country/TerritoryUnited States
CityAnaheim, CA
Period10/7/0210/10/02

Keywords

  • Anomaly detection
  • Scalability
  • User level detection

Fingerprint

Dive into the research topics of 'Towards the scalable implementation of a user level anomaly detection system'. Together they form a unique fingerprint.

Cite this