Challenging the anomaly detection paradigm: a provocative discussion

NSPW '06: Proceedings of the 2006 workshop on New security paradigms(2006)

引用 183|浏览0
暂无评分
摘要
In 1987, Dorothy Denning published the seminal paper on anomaly detection as applied to intrusion detection on a single system. Her paper sparked a new paradigm in intrusion detection research with the notion that malicious behavior could be distinguished from normal system use. Since that time, a great deal of anomaly detection research based on Denning's original premise has occurred. However, Denning's assumptions about anomalies that originate on a single host have been applied essentially unaltered to networks. In this paper we question the application of Denning's work to network based anomaly detection, along with other assumptions commonly made in network-based detection research. We examine the assumptions underlying selected studies of network anomaly detection and discuss these assumptions in the context of the results from studies of network traffic patterns. The purpose of questioning the old paradigm of anomaly detection as a strategy for network intrusion detection is to reconfirm the paradigm as sound or begin the process of replacing it with a new paradigm in light of changes in the operating environment.
更多
查看译文
关键词
anomaly detection,anomaly detection research,network anomaly detection,network traffic pattern,new paradigm,dorothy denning,network intrusion detection,intrusion detection research,intrusion detection,provocative discussion,anomaly detection paradigm,network-based detection research,security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要