POSTER: Revisiting anomaly detection system design philosophy

  • Authors:
  • Ayesha Binte Ashfaq;Muhammad Qasim Ali;Ehab Al-Shaer;Syed Ali Khayam

  • Affiliations:
  • National University of Sciences and Technology, Islamabad, Pakistan;University of North Carolina Charlotte, Charlotte, N. Carolina, USA;University of North Carolina Charlotte, Charlotte, N. Carolina, USA;PLUMgrid Inc, Sunnyvale, California, USA

  • Venue:
  • Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

The inherent design of anomaly detection systems (ADSs) make them highly susceptible to evasion attacks and hence their wide-spread commercial deployment has not been witnessed. There are two main reasons for this: 1) ADSs incur high false positives; 2) Are highly susceptible to evasion attacks (false negatives). While efforts have been made to minimize false positives, evasion is still an open problem. We argue that ADSs design is inherently flawed since it relies on the ADS's detection logic and feature space which is trivial to estimate. In information security e.g. cryptographic algorithms (such as DES), security is inherently dependent upon the key and not the algorithm, which makes these systems very robust by rendering evasion computationally infeasible. We believe there is a need to redesign the anomaly detection systems similar to cryptographic systems. We propose to randomize the feature space of an ADS such that it acts as a cryptographic key for the ADS and hence this randomized feature space is used by the ADS logic for detection of anomalies. This would make the evasion of the ADS computationally infeasible for the attacker.