Using data field to analyze network intrusions

  • Authors:
  • Feng Xie;Shuo Bai

  • Affiliations:
  • ,Software Department, Inst. of Computing Tech., Chinese Academy of Science, Beijing, P.R. China;Software Department, Inst. of Computing Tech., Chinese Academy of Science, Beijing, P.R. China

  • Venue:
  • ISPEC'06 Proceedings of the Second international conference on Information Security Practice and Experience
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we propose a new approach to detect network attacks. Network connections are first transformed into data points in the feature space we predetermined. With the field concept in physics, we consider each point like an electric charge exerts a force on others around it and therefore forms a field which we call data field. Each incoming data object would obtain an amount of the potential energy from the field, from which we can recognize the class of such object. We evaluated our approach over KDD Cup 1999 data set. Experimental results show most attacks can be correctly discriminated in our data field and the false positive rate is acceptable. Compared with other approaches, our method has the better performance in detection of PROBE and U2R attacks.