Revista Tecnologia (May 2009)

Detecting Computer Network Attacks Using Statistical Discriminators and Cluster Analysis.

  • Raimir Holanda,
  • José Everardo Bessa Maia,
  • Marcus Fábio Fontenelle do Carmo

Journal volume & issue
Vol. 28, no. 1

Abstract

Read online

Attacks represent a serious threat to a network environment, and therefore need to be promptly detected. New attack types, of which detection systems may not even be aware, are the most difficult to detect. Currently, the available methods are mainly based on signature or learning algorithms and generally cannot detect these new attacks. The approach presented here uses a small number of statistical discriminators and cluster analysis to detect attacks, obtaining results which are better than the results found in previous papers. Cluster analysis is an unsupervised technique and, therefore, it is able to detect new attacks. We performed an empirical test using real traces.

Keywords