Real-time Anomaly Detection of Network Intrusions

Yong WANG,Liang GAO,Hui-hua YANG
DOI: https://doi.org/10.3969/j.issn.1673-808X.2005.05.001
2005-01-01
Abstract:Most of IDS in current use are based on feature match.They usually appear incapable of detecting unknown intrusion.Anomaly detection can efficiently undertake the work of unknown intrusion detection.MIT's Lincoln Laboratory presented a well-renowned off-line intrusion detection scheme,but it couldn't lend itself to establishing a real-time intrusion detection system(IDS).As a response to this problem,we introduce in this paper a novel real-time IDS method.It dynamically reconstructs the TCP connections,extracts 31 intrusion features,and uses support vector machines as detector.The experiments show that the detection accuracy is above 95%.In order to cut down detect time,we present an algorithm to search best time for detection intrusion.A series of network intrusion experiments have demonstrated that the proposed method can precisely detect intrusions occurring in a local area network within 250 ms.
What problem does this paper attempt to address?