Internet Sieve: An Architecture for Generating Resilient Signatures

dc.contributor.authorYegneswaran, Vinoden_US
dc.contributor.authorGiffin, Jonathonen_US
dc.contributor.authorBarford, Paulen_US
dc.contributor.authorJha, Someshen_US
dc.date.accessioned2012-03-15T17:18:18Z
dc.date.available2012-03-15T17:18:18Z
dc.date.created2004en_US
dc.date.issued2004en_US
dc.description.abstractWe present iSieve, a modular architecture for identifying intrusion profiles in packet trace data and automatically constructing resilient signatures for the profiles. The first component of the architecture organizes and normalizes packet trace data collected from honeynets. The second component classifies this data into attack profiles based upon data similarity measures. The final component uses machine learning methods to generate an automaton for each attack profile. These automata can then be used as signatures by network intrusion detection systems. We show how a large, diverse data set is effectively summarized by each component of our system and use these results to highlight implementation considerations in the architecture. Evaluation demonstrates Sieve's ability to generate resilient signatures for many different intrusion profiles. For example, our learned signatures detect 99.98% of the intrusive sessions in NetBIOS data and generate no false alarms.en_US
dc.format.mimetypeapplication/pdfen_US
dc.identifier.citationTR1507en_US
dc.identifier.urihttp://digital.library.wisc.edu/1793/60402
dc.publisherUniversity of Wisconsin-Madison Department of Computer Sciencesen_US
dc.titleInternet Sieve: An Architecture for Generating Resilient Signaturesen_US
dc.typeTechnical Reporten_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
TR1507.pdf
Size:
3.03 MB
Format:
Adobe Portable Document Format