Multiple Self-Organizing Maps for Intrusion Detection

作者: James A. Mahaffey , James D. Cannady Jr. , Brandon Craig Rhodes

DOI:

关键词:

摘要: The Kohonen self-organizing map is an extremely powerful mechanism for automatic mathematical characterization of acceptable system activity. Because it spontaneously develops a sophisticated the whose behaviors trained to recognize, could detect intrusions which has never observed simply by noting degree they differ from normal After discussing design network monitoring would maximize potential map, we describe briefly our experimental results in simpler resoundingly detected two different exploits perpetrated against one servers.

参考文章(6)
Teuvo Kohonen, Self-Organizing Maps ,(1995)
H. Debar, M. Becker, D. Siboni, A neural network component for an intrusion detection system ieee symposium on security and privacy. pp. 240- 250 ,(1992) , 10.1109/RISP.1992.213257
D.E. Denning, An Intrusion-Detection Model IEEE Transactions on Software Engineering. ,vol. 13, pp. 222- 232 ,(1987) , 10.1109/TSE.1987.232894
C. Cowan, F. Wagle, Calton Pu, S. Beattie, J. Walpole, Buffer overflows: attacks and defenses for the vulnerability of the decade darpa information survivability conference and exposition. ,vol. 2, pp. 119- 129 ,(2000) , 10.1109/DISCEX.2000.821514
C. Cowan, P. Wagle, C. Pu, S. Beattie, J. Walpole, Buffer overflows: attacks and defenses for the vulnerability of the decade Foundations of Intrusion Tolerant Systems, 2003 [Organically Assured and Survivable Information Systems]. pp. 227- 237 ,(2003) , 10.1109/FITS.2003.1264935