作者: Andrew H. Sung , Srinivas Mukkamala
DOI: 10.1007/978-3-540-30502-6_34
关键词:
摘要: Cyber security is a serious global concern. The potential of cyber terrorism has posed threat to national security; meanwhile the increasing prevalence malware and incidents attacks hinder utilization Internet its greatest benefit incur significant economic losses individuals, enterprises, public organizations. This paper presents some recent advances in intrusion detection, feature selection, detection. In stealthy low profile that include only few carefully crafted packets over an extended period time delude firewalls detection system (IDS) have been difficult detect. In protection against (trojans, worms, viruses, etc.), how detect polymorphic metamorphic versions recognized using static scanners great challenge. We present this agent based IDS architecture capable detecting probe at originating host denial service (DoS) boundary controllers. We investigate compare performance different classifiers implemented for purposes. Further, we study real-time probes DoS attacks, with respect data collected on real operating network includes variety simulated attacks. Feature selection as important it many other modeling problems. several techniques their application. It demonstrated that, appropriately chosen features, both can be detected or near controllers. We also briefly encouraging results advanced static, signature-based scanning techniques.