Meta IDS Environments: An Event Message Anomaly Detection Approach

  • Authors:
  • Jens Tolle;Marko Jahnke;Michael Bussmann;Sven Henkel

  • Affiliations:
  • Research Establishment for Applied Science;Research Establishment for Applied Science;Research Establishment for Applied Science;Research Establishment for Applied Science

  • Venue:
  • IWIA '05 Proceedings of the Third IEEE International Workshop on Information Assurance
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents an anomaly detection approach for application in Meta IDS environments, where locally generated event messages from several domains are centrally processed. The basicapproach has been successfully used for detection of abnormal traffic structures in computer networks. It creates directed graphs from address specifications contained within event messages and generates clusterings of the graphs. Large differences between subsequent clusterings indicate anomalies. This anomaly detection approach is part of an intrusion warning system (IWS) for dynamic coalition environments. It is designed to indicate suspisious actions and tendencies and to provide decision support on how to react on anomalies. Real-world data, mixed with data from a simulated internet worm, is used to analyze the system. The results prove the applicability of our approach.