Unexpected-Behavior Detection Using TopK Rankings for Cybersecurity
Cargando...
Fecha
Título de la revista
ISSN de la revista
Título del volumen
Editor
MDPI
Resumen
Anomaly-based intrusion detection systems use profiles to characterize expected behavior of network users. Most of these systems characterize the entire network traffic within a single profile. This work proposes a user-level anomaly-based intrusion detection methodology using only the user’s network traffic. The proposed profile is a collection of TopK rankings of reached services by the user. To detect unexpected behaviors, the real-time traffic is organized into TopK rankings and compared to the profile using similarity measures. The experiments demonstrated that the proposed methodology was capable of detecting a particular kind of malware attack in all the users tested.
Descripción
Palabras clave
Cibersecurity, Intrusion Detection System, Profiling, Network Security, ToK Ranking
Citación
Parres-Peredo, A.I.; Piza-Dávila, H.I.; Cervantes, F. Unexpected-Behavior Detection Using TopK Rankings for Cybersecurity. Appl. Sci. vol. 9 no. 20, pp. 4381, 2019.