UMI  
ProQuest® Dissertations & Theses
The world's most comprehensive collection of dissertations and theses. Learn more...
ProQuest  
 
 
Statistical characteristics and models of cyber attack and norm data for cyber attack detection
by Ayutyanont, Napatkamon, PhD, ARIZONA STATE UNIVERSITY, 2007, 0 pages; 3287905
 

Abstract: Two conventional cyber attack detection approaches, signature recognition and anomaly detection, have drawbacks affecting detection accuracy. While each of the two approaches relies on either the norm or attack data model, the actual attacks mostly occur when the norm activities are also present in the background, resulting in lower detection accuracy. A newly proposed attack-norm separation approach, rooted in the physical world's signal-noise separation method, has been developed to overcome the problems of the conventional approaches. The new approach requires the definition of both an attack and norm data models based on data characteristics of attack and norm activities. The noise (norm data) cancellation in the observed data mixture of attack and norm activities is carried out using the norm model and the identification of the attack, as the signal is carried out using the attack model. Since the attack-norm separation approach relies on the scientific understanding of data characteristics of attack and norm activities to define the attack and norm data models, this dissertation presents the discovery of the data characteristics of attack and norm activities based on the data features of mean, autocorrelation and probability distribution. Detection models are developed for each combination of attack and norm activities by applying Cuscore statistics with the attack and norm models which are defined based on mean, autocorrelation and probability distribution features, respectively. Specifically, activity, state and performance data are collected during the attack and norm activities through the Windows Performance Objects monitoring utility. For variables with the significant mean shift during the attack condition as identified by Mann-Whitney U test, the attack and norm models based on the mean feature are developed to be used for attack detection. For the data variables with changes in degree of autocorrelation characteristics, the best fitted autoregressive integrating moving average (ARIMA) time series models are developed for attack and norm data models to be used in the detection model. For the data variables with changes in probability distribution characteristics, the cumulative empirical distribution functions are used to generate data from the norm and attack models for building the detection model. The detection models developed under the attack-norm separation approach based on the mean, autocorrelation, and probability distribution features show better performance in both detection accuracy and earliness than those of signature recognition based artificial neural networks (ANNs). They also outperform exponentially weighted moving average (EWMA) control charts falling into the conventional attack detection approaches of anomaly detection.

 
Advisor: NULL
School: ARIZONA STATE UNIVERSITY
Source: DAI-B 68/11, p. 7420, May 2008
Source Type: PhD
Subjects: Computer science
Publication Number: 3287905
     
Adobe PDF Access the complete dissertation:
 

» Find an electronic copy at your library.
  Use the link below to access a full citation record of this graduate work:
  http://gateway.proquest.com/openurl%3furl_ver=Z39.88-2004%26res_dat=xri:pqdiss%26rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation%26rft_dat=xri:pqdiss:3287905
  If your library subscribes to the ProQuest Dissertations & Theses (PQDT) database, you may be entitled to a free electronic version of this graduate work. If not, you will have the option to purchase one, and access a 24 page preview for free (if available).

 
 
 

About ProQuest Dissertations & Theses
With over 2.3 million records, the ProQuest Dissertations & Theses (PQDT) database is the most comprehensive collection of dissertations and theses in the world. It is the database of record for graduate research.

The database includes citations of graduate works ranging from the first U.S. dissertation, accepted in 1861, to those accepted as recently as last semester. Of the 2.3 million graduate works included in the database, ProQuest offers more than 1.9 million in full text formats. Of those, over 860,000 are available in PDF format. More than 60,000 dissertations and theses are added to the database each year.

If you have questions, please feel free to visit the ProQuest Web site - http://www.il.proquest.com - or call ProQuest Hotline Customer Support at 1-800-521-3042.



Copyright © 2007 ProQuest. All rights reserved. Terms and Conditions

ProQuest