Abstract
We present Poseidon, a new anomaly based intrusion detection system. Poseidon is payload-based, and presents a two-tier architecture: the first stage consists of a Self-Organizing Map, while the second one is a modified PAYL system. Our benchmarks on the 1999 DARPA data set show a higher detection rate and lower number of false positives than PAYL and PHAD.
Original language | English |
---|---|
Title of host publication | Fourth IEEE International Workshop on Information Assurance (IWIA 2006) |
Subtitle of host publication | proceedings, 13-14 April 2006, Royal Holloway, United Kingdom |
Editors | Jack Cole, Stephen D. Wolthusen |
Place of Publication | Los Alamitos, CA |
Publisher | IEEE |
Pages | 144-156 |
Number of pages | 10 |
ISBN (Print) | 0-7695-2564-4 |
DOIs | |
Publication status | Published - Apr 2006 |
Event | 4th IEEE International Workshop on Information Assurance, IWIA 2006 - London, United Kingdom Duration: 13 Apr 2006 → 14 Apr 2006 Conference number: 4 |
Workshop
Workshop | 4th IEEE International Workshop on Information Assurance, IWIA 2006 |
---|---|
Abbreviated title | IWIA |
Country/Territory | United Kingdom |
City | London |
Period | 13/04/06 → 14/04/06 |
Keywords
- security of data
- SCS-Cybersecurity
- METIS-237425
- self-organising feature maps
- Computer Networks
- telecommunication security
- EWI-1326
- IR-64935