Steps towards autonomous network security: unsupervised detection of network attacks - Université Toulouse III - Paul Sabatier - Toulouse INP Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

Steps towards autonomous network security: unsupervised detection of network attacks

Résumé

The unsupervised detection of network attacks represents an extremely challenging goal. Current methods rely on either very specialized signatures of previously seen attacks, or on expensive and difficult to produce labeled traffic datasets for profiling and training. In this paper we present a completely unsupervised approach to detect attacks, without relying on signatures, labeled traffic, or training. The method uses robust clustering techniques to detect anomalous traffic flows, sequentially captured in a temporal sliding-window basis. The structure of the anomaly identified by the clustering algorithms is used to automatically construct specific filtering rules that characterize its nature, providing easy-to-interpret information to the network operator. In addition, these rules are combined to create an anomaly signature, which can be directly exported towards standard security devices like IDSs, IPSs, and/or Firewalls. The clustering algorithms are highly adapted for parallel computation, which permits to perform the unsupervised detection and construction of signatures in an online basis. We evaluate the performance of this new approach to discover and to build signatures for different network attacks without any previous knowledge, using real traffic traces. Results show that knowledge-independent detection and characterization of network attacks is possible, opening the door to a whole new generation of autonomous security algorithms.
Fichier principal
Vignette du fichier
PID1066608.pdf (148.69 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-00667917 , version 1 (08-02-2012)

Identifiants

  • HAL Id : hal-00667917 , version 1

Citer

Pedro Casas, Johan Mazel, Philippe Owezarski. Steps towards autonomous network security: unsupervised detection of network attacks. 4th IFIP International Conference on New Technologies, Mobility and Security (NTMS'2011), Feb 2011, Paris, France. 6p. ⟨hal-00667917⟩
104 Consultations
170 Téléchargements

Partager

Gmail Facebook X LinkedIn More