A new intrusion detection approach based on network tomography

Hongjie Sun,Binxing Fang,Hongli Zhang
2006-01-01
WSEAS TRANSACTIONS ON INFORMATION SCIENCE AND APPLICATIONS
Abstract:The more and more complicated and advanced network attacks greatly thread the security of network. It is difficult to collect the network internal link character directly, because present networks have evolved into large and complex systems that are decentralized and loosely controlled. Network tomography is a new concept proposed for estimating internal network structure and link-level performance from end-to-end measurements and it gives a new direction to solve intrusion detection problem. In order to detect and locate the source of anomaly and attack in the beginning of their spreading, we abstract the required link-level properties of network performance using end-to-end measurements and propose a new approach using maximum likelihood estimation and neural network for anomaly link detection and location. Maximum likelihood estimation is used to estimate the distribution of link character, a mixing and optimizing neural network solution combining the Back Propagation (BP) Algorithm with the Simulated Annealing (SA) Algorithm is used for link activity profile learning and anomaly link detection. Comparing with single BP algorithm, the value calculation result shows that BP-SA mixing and optimizing solution has a higher speed and higher accuracy. Experiment results indicate the new approach is effective and of a definite practicability. It is a bran-new idea and has a further develop potential for large scale network anomaly detection.
What problem does this paper attempt to address?