Normal profile updating method for enhanced packet header anomaly detection

3Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

There is a significant need for various Intrusion Detection Systems (IDS) methods for packet behavior anomaly detection, due to the consistent exposure of packets to frequent intrusion threats. Thus, Packet Header Anomaly Detection (PHAD) considered as one of many significant approaches that is used for detecting threats on network packet. However, this approach still suffers from high generation of false alarm rate. This paper investigates a Normal Profile Updating Method (NPUM) for enhancing the PHAD based IDS model. This method updates normal profile of anomaly IDS using further processing of both the normal and abnormal data identified by anomaly detector. Simulation experiments and DARPA intrusion detection evaluation data sets are used for testing the proposed method. Results show that the proposed method can reduce the false positive alarms and improve the performance in terms of accuracy of detection. The major contributions of this research include the design of an enhanced PHAD-based IDS. This would contribute toward the enhanced IDSs to strengthen network security.

Cite

CITATION STYLE

APA

Alsharafi, W. M., Omar, M. N., Al-Majmar, N. A., & Fazea, Y. (2020). Normal profile updating method for enhanced packet header anomaly detection. In Advances in Intelligent Systems and Computing (Vol. 1073, pp. 734–747). Springer. https://doi.org/10.1007/978-3-030-33582-3_69

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free