NATE: Network Analysis of Anomalous Traffic Events, a low-cost approach

  • Authors:
  • Carol Taylor;Jim Alves-Foss

  • Affiliations:
  • University of Idaho, Moscow, Idaho;University of Idaho, Moscow, Idaho

  • Venue:
  • Proceedings of the 2001 workshop on New security paradigms
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

A new approach to network intrusion detection is needed to solve the monitoring problems of high volume network data and the time constraints for Intrusion Detection System (IDS) management. Most current network IDS's have not been specifically designed for high speed traffic or low maintenance. We propose a solution to these problems which we call NATE, Network Analysis of Anomalous Traffic Events. Our approach features minimal network traffic measurement, an anomaly-based detection method, and a limited attack scope. NATE is similar to other lightweight approaches in its simplified design, but our approach, being anomaly based, should be more efficient in both operation and maintenance than other lightweight approaches. We present the method and perform an empirical test using MIT Lincoln Lab's data.