Sciweavers

ACSAC
2008
IEEE

Behavior-Profile Clustering for False Alert Reduction in Anomaly Detection Sensors

13 years 6 months ago
Behavior-Profile Clustering for False Alert Reduction in Anomaly Detection Sensors
Anomaly Detection (AD) sensors compute behavior profiles to recognize malicious or anomalous activities. The behavior of a host is checked continuously by the AD sensor and an alert is raised when the behavior deviates from its behavior profile. Unfortunately, the majority of AD sensors suffer from high volumes of false alerts either maliciously crafted by the host or originating from insufficient training of the sensor. We present a cluster-based AD sensor that relies on clusters of behavior profiles to identify anomalous behavior. The behavior of a host raises an alert only when a group of host profiles with similar behavior (cluster of behavior profiles) detect the anomaly, rather than just relying on the host's own behavior profile to raise the alert (singleprofile AD sensor). A cluster-based AD sensor significantly decreases the volume of false alerts by providing a more robust model of normal behavior based on clusters of behavior profiles. Additionally, we introduce an arc...
Vanessa Frías-Martínez, Salvatore J.
Added 12 Oct 2010
Updated 12 Oct 2010
Type Conference
Year 2008
Where ACSAC
Authors Vanessa Frías-Martínez, Salvatore J. Stolfo, Angelos D. Keromytis
Comments (0)