Intrusion Detection System Using Discrete Fourier Transform with Window Function

Autor: Hidema Tanaka, Yusuke Tsuge
Rok vydání: 2016
Předmět:
Zdroj: International Journal of Network Security & Its Applications. 8:23-34
ISSN: 0974-9330
0975-2307
DOI: 10.5121/ijnsa.2016.8202
Popis: An Intrusion Detection System (IDS) is counter measure against network attack. There are mainly two types of detections; signature-based and anomaly-based. And there are two kinds of error; false negative and false positive. In development of IDS, establishment of a method to reduce such false is a major issue. In this paper, we propose a new anomaly-based detection method using Discrete Fourier Transform (DFT)with window function. In our method, we assume fluctuation of payload in ordinary sessions as random. On the other hand, we can see fluctuation in attack sessions have bias. From the view point of spectrum analysis based on such assumption, we can find out different characteristic in spectrum of attack sessions. Using the characteristic, we can detect attack sessions. Example detection against Kyoto 2006+ data set shows 12.0% of false positive at most,and 0.0% of false negative.
Databáze: OpenAIRE