The application of bioinformatics to network intrusion detection

Research output: Chapter in Book/Report/Conference proceedingConference contribution

5 Citations (Scopus)

Abstract

In this paper, a novel approach that applies bioinformatics algorithms to network intrusion detection is proposed. Network intrusion detection is the problem to detect security violations on or through a network. Misuse detection approach of network intrusion detection which is widely deployed on today's network environment requires precise signature data and occasionally fails to detect variants of known attacks or new types of attack. Bioinformatics is a discipline where various techniques from mathematics, statistics, and computer science are utilized to solve biological problems. The biological problems often include finding specific patterns in large sequence of complex data. Both intrusion detection and bioinformatics have the similar problem, detection of certain patterns in large sequences of strings. By utilizing such common feature our proposing approach uses sequence alignment techniques from bioinformatics that have been used to quantify and visualize similarity between DNA and protein sequences, to align sequences of network traffic patterns and to evaluate how an access is similar to known attack patterns. There have been several researches utilizing bioinformatics techniques for host based intrusion detection systems that detect anomalous behavior on each host by monitoring sequences of user commands or sequences of system calls invoked by applications. Uniqueness of our approach is to apply sequence alignment algorithms to detect variant of network based attacks in captured network traffic data. We examined several techniques from bioinformatics to apply. An application which uses local alignment and global alignment is underdevelopment. The system scores similarity between monitored network traffic and known attack signatures.

Original languageEnglish
Title of host publication39th Annual 2005 International Carnahan Conference on Security Technology, CCST'05
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Print)0780392450, 9780780392458
DOIs
Publication statusPublished - 2005
Externally publishedYes
Event39th Annual 2005 International Carnahan Conference on Security Technology, CCST'05 - Las Palmos, Spain
Duration: 2005 Oct 112005 Oct 14

Publication series

NameProceedings - International Carnahan Conference on Security Technology
ISSN (Print)1071-6572

Conference

Conference39th Annual 2005 International Carnahan Conference on Security Technology, CCST'05
Country/TerritorySpain
CityLas Palmos
Period05/10/1105/10/14

ASJC Scopus subject areas

  • Engineering(all)

Fingerprint

Dive into the research topics of 'The application of bioinformatics to network intrusion detection'. Together they form a unique fingerprint.

Cite this