Poseidon: a 2-tier Anomaly-based Network Intrusion Detection System

D. Bolzoni, Emmanuele Zambon, Sandro Etalle, Pieter H. Hartel

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    70 Citations (Scopus)
    73 Downloads (Pure)

    Abstract

    We present Poseidon, a new anomaly based intrusion detection system. Poseidon is payload-based, and presents a two-tier architecture: the first stage consists of a Self-Organizing Map, while the second one is a modified PAYL system. Our benchmarks on the 1999 DARPA data set show a higher detection rate and lower number of false positives than PAYL and PHAD.
    Original languageEnglish
    Title of host publicationFourth IEEE International Workshop on Information Assurance (IWIA 2006)
    Subtitle of host publicationproceedings, 13-14 April 2006, Royal Holloway, United Kingdom
    EditorsJack Cole, Stephen D. Wolthusen
    Place of PublicationLos Alamitos, CA
    PublisherIEEE
    Pages144-156
    Number of pages10
    ISBN (Print)0-7695-2564-4
    DOIs
    Publication statusPublished - Apr 2006
    Event4th IEEE International Workshop on Information Assurance, IWIA 2006 - London, United Kingdom
    Duration: 13 Apr 200614 Apr 2006
    Conference number: 4

    Workshop

    Workshop4th IEEE International Workshop on Information Assurance, IWIA 2006
    Abbreviated titleIWIA
    Country/TerritoryUnited Kingdom
    CityLondon
    Period13/04/0614/04/06

    Keywords

    • security of data
    • SCS-Cybersecurity
    • METIS-237425
    • self-organising feature maps
    • Computer Networks
    • telecommunication security
    • EWI-1326
    • IR-64935

    Fingerprint

    Dive into the research topics of 'Poseidon: a 2-tier Anomaly-based Network Intrusion Detection System'. Together they form a unique fingerprint.

    Cite this