Presentation is loading. Please wait.

Presentation is loading. Please wait.

ONR MURI area: High Confidence Real-Time Misuse and Anomaly Detection

Similar presentations


Presentation on theme: "ONR MURI area: High Confidence Real-Time Misuse and Anomaly Detection"— Presentation transcript:

1 ONR MURI area: High Confidence Real-Time Misuse and Anomaly Detection
Intrusion and Anomaly Detection in Network Traffic Streams: Checking and Machine Learning Approaches ONR MURI area: High Confidence Real-Time Misuse and Anomaly Detection

2 Framework and System Architecture for Anomaly and Intrusion Detection
Sampath Kannan Insup Lee Oleg Sokolsky Wenke Lee Diana Spears William Spears Linda Zhao

3 Overview Our approach is based on integration of a variety of anomaly and intrusion detection techniques A uniform mechanism and architecture is needed to support the integration Requirements: Flexibility Transparency Efficiency

4 MaC-based IDS

5 Background: MaC system
MaC has been designed for run-time verification of software systems Main features: Checker decoupled from the system Event recognizer extracts relevant events from input stream Impact on reduced checking overhead

6 Background: MaC architecture

7 MaC extensions for IDS Multiple specification languages
Dynamic property adjustment Checking of probabilistic properties

8 Integration architecture
Unsupervised learner Cluster identification routines provide new detection rules Supervised learner Logistic regression modeling Tree-based algorithms Support vector machines

9 Integration architecture


Download ppt "ONR MURI area: High Confidence Real-Time Misuse and Anomaly Detection"

Similar presentations


Ads by Google