University of Maryland DRUM  
University of Maryland Digital Repository at the University of Maryland

DRUM >
Theses and Dissertations from UMD >
UMD Theses and Dissertations >

Please use this identifier to cite or link to this item: http://hdl.handle.net/1903/2571

Title: On-line Adaptive IDS Scheme for Detecting Unknown Network Attacks using HMM Models
Authors: Bojanic, Irena
Advisors: Baras, John S
Department/Program: Electrical Engineering
Type: Thesis
Sponsors: Digital Repository at the University of Maryland
University of Maryland (College Park, Md.)
Keywords: Engineering, Electronics and Electrical (0544)
IDS; network security; intrusions
Issue Date: 4-May-2005
Abstract: An important problem in designing IDS schemes is an optimal trade-off between good detection and false alarm rate. Specifically, in order to detect unknown network attacks, existing IDS schemes use anomaly detection which introduces a high false alarm rate. In this thesis we propose an IDS scheme based on overall behavior of the network. We capture the behavior with probabilistic models (HMM) and use only limited logic information about attacks. Once we set the detection rate to be high, we filter out false positives through stages. The key idea is to use probabilistic models so that even an unknown attack can be detected, as well as a variation of a previously known attack. The scheme is adaptive and real-time. Simulation study showed that we can have a perfect detection of both known and unknown attacks while maintaining a very low false alarm rate.
URI: http://hdl.handle.net/1903/2571
Appears in Collections:UMD Theses and Dissertations
Electrical & Computer Engineering Theses and Dissertations

Files in This Item:

File Description SizeFormatNo. of Downloads
umi-umd-2458.pdf1.22 MBAdobe PDF1385View/Open

All items in DRUM are protected by copyright, with all rights reserved.

 

DRUM is brought to you by the University of Maryland Libraries
University of Maryland, College Park, MD 20742-7011 (301)314-1328.
Please send us your comments. -
All Contents