The Experts below are selected from a list of 19980 Experts worldwide ranked by ideXlab platform
Joseph G Tront - One of the best experts on this subject based on the ideXlab platform.
-
mobile device profiling and intrusion Detection using smart batteries
Hawaii International Conference on System Sciences, 2008Co-Authors: T K Buennemeyer, Randy Marchany, T M Nelson, L M Clagett, John P Dunning, Joseph G TrontAbstract:This paper introduces capabilities developed for a battery-sensing intrusion protection system (B-SIPS) for mobile computers, which alerts when abnormal current changes are detected. The intrusion Detection system's (IDS's) IEEE 802.15.1 (Bluetooth) and 802.11 (Wi-Fi) capabilities are enhanced with iterative safe process checking, wireless connection determination, and an automated intrusion protection disconnect ability. The correlation intrusion Detection Engine (CIDE) provides power profiling for mobile devices and a correlated view of B-SIPS and snort alerts. An examination of smart battery drain times was conducted to ascertain the optimal transmission rate for the B-SIPS client. A 10 second reporting rate was used to assess 9 device types, which were then compared with their corresponding baseline battery lifetime. Lastly, an extensive usability study was conducted to improve the B-SIPS client and CIDE features. The 31 expert participants provided feedback and data useful for validating the system's viability as a complementary IDS for mobile devices.
-
battery sensing intrusion protection for wireless handheld computers using a dynamic threshold calculation algorithm for attack Detection
Hawaii International Conference on System Sciences, 2007Co-Authors: T K Buennemeyer, F Munshi, Randy Marchany, Joseph G TrontAbstract:This paper proposes a pioneering battery-sensing intrusion protection system (B-SIPS) for mobile computers, which alerts on power changes detected on small wireless devices, using an innovative dynamic threshold calculation algorithm. B-SIPS enabled hosts are employed as sensors in a wireless network and form the basis of the intrusion Detection system (IDS). This Detection capability is scalable and complementary with existing commercial and open system network IDSs. B-SIPS implementation correlates device power consumption with IEEE 802.11 Wi-Fi and 802.15.1 Bluetooth communication activity. Irregular and attack activity is detected and reported to the intrusion Detection Engine for correlation with existing signatures in a database and for forensic investigation by a security manager
T K Buennemeyer - One of the best experts on this subject based on the ideXlab platform.
-
mobile device profiling and intrusion Detection using smart batteries
Hawaii International Conference on System Sciences, 2008Co-Authors: T K Buennemeyer, Randy Marchany, T M Nelson, L M Clagett, John P Dunning, Joseph G TrontAbstract:This paper introduces capabilities developed for a battery-sensing intrusion protection system (B-SIPS) for mobile computers, which alerts when abnormal current changes are detected. The intrusion Detection system's (IDS's) IEEE 802.15.1 (Bluetooth) and 802.11 (Wi-Fi) capabilities are enhanced with iterative safe process checking, wireless connection determination, and an automated intrusion protection disconnect ability. The correlation intrusion Detection Engine (CIDE) provides power profiling for mobile devices and a correlated view of B-SIPS and snort alerts. An examination of smart battery drain times was conducted to ascertain the optimal transmission rate for the B-SIPS client. A 10 second reporting rate was used to assess 9 device types, which were then compared with their corresponding baseline battery lifetime. Lastly, an extensive usability study was conducted to improve the B-SIPS client and CIDE features. The 31 expert participants provided feedback and data useful for validating the system's viability as a complementary IDS for mobile devices.
-
battery sensing intrusion protection for wireless handheld computers using a dynamic threshold calculation algorithm for attack Detection
Hawaii International Conference on System Sciences, 2007Co-Authors: T K Buennemeyer, F Munshi, Randy Marchany, Joseph G TrontAbstract:This paper proposes a pioneering battery-sensing intrusion protection system (B-SIPS) for mobile computers, which alerts on power changes detected on small wireless devices, using an innovative dynamic threshold calculation algorithm. B-SIPS enabled hosts are employed as sensors in a wireless network and form the basis of the intrusion Detection system (IDS). This Detection capability is scalable and complementary with existing commercial and open system network IDSs. B-SIPS implementation correlates device power consumption with IEEE 802.11 Wi-Fi and 802.15.1 Bluetooth communication activity. Irregular and attack activity is detected and reported to the intrusion Detection Engine for correlation with existing signatures in a database and for forensic investigation by a security manager
Vasilis Maglaris - One of the best experts on this subject based on the ideXlab platform.
-
one step ahead to multisensor data fusion for ddos Detection
ACM Symposium on Applied Computing, 2005Co-Authors: Christos Siaterlis, Vasilis MaglarisAbstract:This work introduces the use of data fusion in the field of DDoS anomaly Detection. We present Dempster-Shafer Theory of Evidence (D-S), the mathematical foundation for the development of a novel DDoS Detection Engine. Based on a data fusion paradigm, we combine evidence generated from multiple simple metrics to feed our D-S inference Engine and detect attacks on a single network element (high bandwidth link).The main advantages of our approach are the modeling power of the Theory of Evidence in expressing beliefs in some hypotheses, its flexibility to handle uncertainty and ignorance and its ability to provide quantitative measurement of the belief and plausibility in our Detection results. Furthermore we propose a system that can be trained (supervised learning) with minimum human effort, using in parallel expert knowledge about each metric Detection ability.We evaluate our Detection Engine prototype through an extensive set of experiments on an operational network using real network traffic, with the use of a popular DDoS attack generator. Based on these results we discuss the performance of our D-S scheme in contrast to simple thresholds on single metrics, as well as against an alternative data fusion technique based on an Artificial Neural Network. We conclude that our data fusion is a promising approach that significantly increases the DDOS Detection rate (true positives) while keeping the false positive alarm rate low.
Thomas Toth - One of the best experts on this subject based on the ideXlab platform.
-
using decision trees to improve signature based intrusion Detection
Lecture Notes in Computer Science, 2003Co-Authors: Christophe Kruegel, Thomas TothAbstract:Most deployed intrusion Detection systems (IDSs) follow a signature-based approach where attacks are identified by matching each input event against predefined signatures that model malicious activity. This matching process accounts for the most resource intensive task of an IDS. Many systems perform the matching by comparing each input event to all rules sequentially. This is far from being optimal. Although sometimes ad-hoc optimizations are utilized, no general solution to this problem has been proposed so far. This paper describes an approach where machine learning clustering techniques are applied to improve the matching process. Given a set of signatures (each dictating a number of constraints the input data must fulfill to trigger it) an algorithm generates a decision tree that is used to find malicious events using as few redundant comparisons as possible. This general idea has been applied to a network-based IDS. In particular, a system has been implemented that replaces the Detection Engine of Snort [14, 16]. Experimental evaluation shows that the speed of the Detection process has been significantly improved, even compared to Snort's recently released, fully revised Detection Engine.
Henry L Owen - One of the best experts on this subject based on the ideXlab platform.
-
wireless intrusion Detection and response a classic study using main in the middle attack
Wireless Communications and Networking Conference, 2004Co-Authors: T R Schmoyer, Yu Xi Lim, Henry L OwenAbstract:Intrusion Detection and countermeasures response is an active area of research. In this paper, we examine integrating an intrusion Detection Engine with an active countermeasure capability. We use a classic man in the middle attack as a case study to specify the integrated wireless intrusion Detection capability with the active countermeasure response. We present a case study in dynamically defending against an example attack in an 802.11 infrastructure basic service set by combining the concepts for a distributed wireless intrusion Detection and response system architecture with adaptive response strategies based on alarm confidence, attack frequency, assessed risks, and estimated response costs. We also include a description of a tool kit we have implemented to prototypically test and evaluate our concepts.