UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

Statistical fingerprint-based intrusion detection system (SF-IDS)

Boero, L; Cello, M; Marchese, M; Mariconti, E; Naqash, T; Zappatore, S; (2017) Statistical fingerprint-based intrusion detection system (SF-IDS). International Journal of Communication Systems , 30 (10) , Article e3225. 10.1002/dac.3225. Green open access

[thumbnail of IJCS-15-0773-revised.pdf]
Preview
Text
IJCS-15-0773-revised.pdf - Accepted Version

Download (233kB) | Preview

Abstract

Intrusion detection systems (IDS) are systems aimed at analyzing and detecting security problems. The IDS may be structured into misuse and anomaly detection. The former are often signature/rule IDS that detect malicious software by inspecting the content of packets or files looking for a “signature” labeling malware. They are often very efficient, but their drawback stands in the weakness of the information to check (eg, the signature), which may be quickly dated, and in the computation time because each packet or file needs to be inspected. The IDS based on anomaly detection and, in particular, on statistical analysis have been originated to bypass the mentioned problems. Instead of inspecting packets, each traffic flow is observed so getting a statistical characterization, which represents the fingerprint of the flow. This paper introduces a statistical analysis based intrusion detection system, which, after extracting the statistical fingerprint, uses machine learning classifiers to decide whether a flow is affected by malware or not. A large set of tests is presented. The obtained results allow selecting the best classifiers and show the performance of a decision maker that exploits the decisions of a bank of classifiers acting in parallel.

Type: Article
Title: Statistical fingerprint-based intrusion detection system (SF-IDS)
Open access status: An open access version is available from UCL Discovery
DOI: 10.1002/dac.3225
Publisher version: https://doi.org/10.1002/dac.3225
Language: English
Additional information: This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions.
Keywords: intrusion detection system, IP, machine learning, networking, statistical analysis
UCL classification: UCL
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Security and Crime Science
URI: https://discovery.ucl.ac.uk/id/eprint/10087252
Downloads since deposit
0Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item