earticle

논문검색

A Dependable Monitoring Mechanism Combining Static and Dynamic Anomaly Detection for Network Systems

초록

영어

Due to abuse by insiders or penetration by outsiders, network systems usually suffer various security issues. In order to achieve high dependable and low cost monitoring, this paper proposes a dependable monitoring mechanism combining static threshold-based and dynamic anomaly detection. Firstly, the performance metrics of host and network are collected through different methods. In static threshold-based detection phase, the secondary metrics are combined to several group items. When any group item exceeds its threshold, dynamic detection methods are adopt to further detect anomaly. In dynamic detection phase, PCA, joint Gaussian distribution, and Bayesian classification are combined to achieve low cost and efficient anomaly detection. Experimental results in a campus-wide network system show that the proposed dependable monitoring mechanism achieves low false negative (FN) rate and low false positive (FP) rate. The proposed monitoring mechanism outperforms PCA & Bayesian, and grouping detection methods.

목차

Abstract
 1. Introduction
 2. Related Work
  2.1. Dependable Monitoring
  2.2. Anomaly detection
 3. Structure of the Dependable Monitoring Mechanism
 4. Data Acquisition
  4.1. Host Data Acquisition
  4.2. Network Data Acquisition
 5. Static and Dynamic Anomaly Detection
  5.1. Static Anomaly Detection
  5.2. Dynamic Anomaly Detection
 6. Experiments and Analysis
  6.1. A Sampled Data Set and PCA Results
  6.2. Experimental Results and Analysis
 7. Conclusion and Future Work
 Acknowledgments
 References

저자정보

  • GuiPing Wang College of Computer Science, Chongqing University, Chongqing, China
  • ShuYu Chen College of Software Engineering, Chongqing University, Chongqing, China
  • Zhen Zhou College of Computer Science, Chongqing University, Chongqing, China
  • MingWei Lin College of Computer Science, Chongqing University, Chongqing, China

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.