Masquerade Intrusion Detection Based on Network Flow Statistical Data

Wen-yi LIU,Zhi XUE,Yi-jun WANG
DOI: https://doi.org/10.3969/j.issn.1000-3428.2014.07.016
2014-01-01
Abstract:Masquerade intrusion is attack by unauthorized users to obtain access to confidential data or conduct other illegal operation. Currently, masquerade detection largely depends on the retrieval of user’s sensitive information to model the user characteristics. To avoid the violation of user privacy, this paper proposes a new masquerade intrusion detection method based on network flow statistical data. User Characteristic modeling is illustrated in details and a hybrid algorithm combining AdaBoost and Support Vector Machine(SVM) is also introduced to train and predict user behavior. Experiments on a real packet data set show that the method can resist masquerade intrusion, preserve user privacy, and its system detection rate is 97.5%, false positive rate is 1.1%when delay is in milliseconds, prove that the detection performance of this method is better than the existing methods.
What problem does this paper attempt to address?