Anomaly-based network intrusion detection: Techniques, systems and challenges
-
Pedro García-Teodoro; Jesús Esteban Díaz Verdejo; Gabriel Maciá-Fernández; Enrique Vazquez
- Abstract:
- The Internet and computer networks are exposed to an increasing number of security
threats. With new types of attacks appearing continually, developing flexible and adaptive
security oriented approaches is a severe challenge. In this context, anomaly-based network
intrusion detection techniques are a valuable technology to protect target systems and
networks against malicious activities. However, despite the variety of such methods
described in the literature in recent years, security tools incorporating anomaly detection
functionalities are just starting to appear, and several important problems remain to be
solved. This paper begins with a review of the most well-known anomaly-based intrusion
detection techniques. Then, available platforms, systems under development and research
projects in the area are presented. Finally, we outline the main challenges to be dealt with
for the wide scale deployment of anomaly-based intrusion detectors, with special
emphasis on assessment issues.
- Research areas:
- Year:
- 2009
- Type of Publication:
- Article
- Journal:
- Computers & Security
- Volume:
- 29
- Pages:
- 18-28
- ISSN:
- 0167-4048
Hits: 2456