• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. An architecture for inline anomaly detection
 
  • Details
  • Full
Options
2008
Conference Paper
Title

An architecture for inline anomaly detection

Abstract
In this paper we propose an intrusion prevention system (IPS) which operates inline and is capable to detect unknown attacks using anomaly detection methods. Incorporated in the framework of a packet filter each incoming packet is analyzed and - according to an internal connection state and a computed anomaly score - either delivered to the production system, redirected to a special hardened system or logged to a network sink for later analysis. Runtime measurements of an actual implementation prove that the performance overhead of the system is sufficient,for inline processing. Accuracy measurements on real network data yield improvements especially in the number of false positives, which are reduced by a factor of five compared to a plain anomaly detector.
Author(s)
Krueger, T.
Gehl, C.
Rieck, K.
Laskov, P.
Mainwork
4th European Conference on Computer Network Defence, EC2ND 2008  
Conference
European Conference on Computer Network Defence (EC2ND) 2008  
DOI
10.1109/EC2ND.2008.8
Language
English
FIRST
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024