Sciweavers

ETRICS
2006

On the Use of Word Networks to Mimicry Attack Detection

14 years 4 months ago
On the Use of Word Networks to Mimicry Attack Detection
Intrusion detection aims at raising an alarm any time the security of an IT system gets compromised. Though highly successful, Intrusion Detection Systems are all susceptible of mimicry attacks [1]. A mimicry attack is a variation of an attack that attempts to pass by as normal behaviour. In this paper, we introduce a method which is capable of successfuly detecting a significant and interesting sub-class of mimicry attacks. Our method makes use of a word network [2, 3]. A word network conveniently decomposes a pattern matching problem into a chain of smaller, noise-tolerant pattern matchers, thereby making it more tractable. A word network is realised as a finite state machine, where every state is a hidden Markov model. Our mechanism has shown a 93% of effectivity, with a false positive rate of 3%.
Fernando Godínez, Dieter Hutter, Raul Monro
Added 22 Aug 2010
Updated 22 Aug 2010
Type Conference
Year 2006
Where ETRICS
Authors Fernando Godínez, Dieter Hutter, Raul Monroy
Comments (0)