POSEIDON: a 2-tier Anomaly-based Network Intrusion Detection System

  • Authors:
  • Damiano Bolzoni;Sandro Etalle;Pieter Hartel;Emmanuele Zambon

  • Affiliations:
  • University of Twente, Netherlands;University of Twente, Netherlands;University of Twente, Netherlands;Universita Ca Foscari di Venezia, Italy

  • Venue:
  • IWIA '06 Proceedings of the Fourth IEEE International Workshop on Information Assurance
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present POSEIDON, a new anomaly-based network intrusion detection system. POSEIDON is payload-based, and has a two-tier architecture: the first stage consists of a Self-Organizing Map, while the second one is a modified PAYL system. Our benchmarks on the 1999 DARPA data set show a higher detection rate and lower number of false positives than PAYL and PHAD.