4.4 Article

An anomaly detection technique based on a chi-square statistic for detecting intrusions into information systems

期刊

出版社

WILEY
DOI: 10.1002/qre.392

关键词

computer security; intrusion detection; multivariate analysis; chi-square statistic

向作者/读者索取更多资源

An intrusion into an information system compromises its security (e.g. availability, integrity and confidentiality) through a series of events in the information system. Intrusive events often show departures (anomalies) from normal events in an information system. This paper presents an anomaly detection technique based on a chi-square statistic. This technique builds a profile of normal events in an information system-a norm profile computes the departure of events in the recent past from the norm profile and detects a large departure as an anomaly-a likely intrusion. This technique was tested for its performance in distinguishing normal events from intrusive events in an information system. The test results demonstrated the promising performance of this technique for intrusion detection in terms of a low false alarm rate and a high detection rate. Intrusive events were detected at a very early stage. Copyright (C) 2001 John Wiley & Sons, Ltd.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.4
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据