发明授权
- 专利标题: Method and system for adaptive anomaly-based intrusion detection
- 专利标题(中): 基于自适应异常入侵检测的方法和系统
-
申请号: US12692165申请日: 2010-01-22
-
公开(公告)号: US08800036B2公开(公告)日: 2014-08-05
- 发明人: Syed Ali Khayam , Muhammad Qasim Ali
- 申请人: Syed Ali Khayam , Muhammad Qasim Ali
- 申请人地址: PK Islamabad
- 专利权人: The School of Electrical Engineering and Computer Science (SEECS), National University of Sciences and Technology (NUST)
- 当前专利权人: The School of Electrical Engineering and Computer Science (SEECS), National University of Sciences and Technology (NUST)
- 当前专利权人地址: PK Islamabad
- 代理机构: Brown & Michaels, PC
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
The input characteristics of a real-time IDS change continuously with time therefore setting a rigid (time and behavior invariant) classification threshold limits the accuracy that the IDS can potentially achieve. A generic threshold tuning method and system is proposed which can adaptively tune the detection threshold of a real-time IDS in accordance with varying host and network behavior. The method and system perform statistical and information-theoretic analysis of network and host-based IDSs' anomaly based intrusions to reveal a consistent time correlation structure between benign activity periods which is used to predict future anomaly scores and to adapt an IDS' detection threshold accordingly.
公开/授权文献
信息查询