Islandia, NY

In 1987, Dorothy Denning published the seminal paper on anomaly detection as applied to intrusion detection on a single system. Her paper sparked a new paradigm in intrusion detection research with the notion that malicious behavior could be distinguished from normal system use. Since that time, a g...

Full description

Bibliographic Details
Main Authors: Carrie Gates, Carol Taylor
Other Authors: The Pennsylvania State University CiteSeerX Archives
Format: Text
Language:English
Subjects:
Online Access:http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.227.6751
http://www.nspw.org/papers/2006/nspw2006-gates.pdf
id ftciteseerx:oai:CiteSeerX.psu:10.1.1.227.6751
record_format openpolar
spelling ftciteseerx:oai:CiteSeerX.psu:10.1.1.227.6751 2023-05-15T16:56:41+02:00 Islandia, NY Carrie Gates Carol Taylor The Pennsylvania State University CiteSeerX Archives application/pdf http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.227.6751 http://www.nspw.org/papers/2006/nspw2006-gates.pdf en eng http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.227.6751 http://www.nspw.org/papers/2006/nspw2006-gates.pdf Metadata may be used without restrictions as long as the oai identifier remains attached to it. http://www.nspw.org/papers/2006/nspw2006-gates.pdf text ftciteseerx 2016-01-07T18:34:35Z In 1987, Dorothy Denning published the seminal paper on anomaly detection as applied to intrusion detection on a single system. Her paper sparked a new paradigm in intrusion detection research with the notion that malicious behavior could be distinguished from normal system use. Since that time, a great deal of anomaly detection research based on Denning’s original premise has occurred. However, Denning’s assumptions about anomalies that originate on a single host have been applied essentially unaltered to networks. In this paper we question the application of Denning’s work to network based anomaly detection, along with other assumptions commonly made in network-based detection research. We examine the assumptions underlying selected studies of network anomaly detection and discuss these assumptions in the context of the results from studies of network traffic patterns. The purpose of questioning the old paradigm of anomaly detection as a strategy for network intrusion detection is to reconfirm the paradigm as sound or begin the process of replacing it with a new paradigm in light of changes in the operating environment. Text Islandia Unknown
institution Open Polar
collection Unknown
op_collection_id ftciteseerx
language English
description In 1987, Dorothy Denning published the seminal paper on anomaly detection as applied to intrusion detection on a single system. Her paper sparked a new paradigm in intrusion detection research with the notion that malicious behavior could be distinguished from normal system use. Since that time, a great deal of anomaly detection research based on Denning’s original premise has occurred. However, Denning’s assumptions about anomalies that originate on a single host have been applied essentially unaltered to networks. In this paper we question the application of Denning’s work to network based anomaly detection, along with other assumptions commonly made in network-based detection research. We examine the assumptions underlying selected studies of network anomaly detection and discuss these assumptions in the context of the results from studies of network traffic patterns. The purpose of questioning the old paradigm of anomaly detection as a strategy for network intrusion detection is to reconfirm the paradigm as sound or begin the process of replacing it with a new paradigm in light of changes in the operating environment.
author2 The Pennsylvania State University CiteSeerX Archives
format Text
author Carrie Gates
Carol Taylor
spellingShingle Carrie Gates
Carol Taylor
Islandia, NY
author_facet Carrie Gates
Carol Taylor
author_sort Carrie Gates
title Islandia, NY
title_short Islandia, NY
title_full Islandia, NY
title_fullStr Islandia, NY
title_full_unstemmed Islandia, NY
title_sort islandia, ny
url http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.227.6751
http://www.nspw.org/papers/2006/nspw2006-gates.pdf
genre Islandia
genre_facet Islandia
op_source http://www.nspw.org/papers/2006/nspw2006-gates.pdf
op_relation http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.227.6751
http://www.nspw.org/papers/2006/nspw2006-gates.pdf
op_rights Metadata may be used without restrictions as long as the oai identifier remains attached to it.
_version_ 1766047890230214656