Network intrusion detection using statistical probability distribution

  • Authors:
  • Gil-Jong Mun;Yong-Min Kim;DongKook Kim;Bong-Nam Noh

  • Affiliations:
  • Interdisciplinary Program of Information Security, Chonnam National University, Gwangju, Korea;Dept. of Electronic Commerce, Chonnam National University, Yeosu, Korea;Div. of Electronics Computer & Information Engineering, Chonnam National University, Gwangju, Korea;Div. of Electronics Computer & Information Engineering, Chonnam National University, Gwangju, Korea

  • Venue:
  • ICCSA'06 Proceedings of the 2006 international conference on Computational Science and Its Applications - Volume Part II
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

It is very difficult to select useful measures and to generate patterns detecting attacks from network. Patterns to detect intrusions are usually generated by expert’s experiences that need a lot of man-power, management expense and time. This paper proposes the statistical methods for detecting attacks without expert’s experiences. The methods are to select the detection measures from features of network connections and to detect attacks. We extracted normal and each attack data from network connections, and selected the measures for detecting attacks by relative entropy. Also we made probability patterns and detected attacks by likelihood ratio. The detection rates and the false positive rates were controlled by the different threshold in the method. We used KDD CUP 99 dataset to evaluate the performance of the proposed methods.