See this document in CiteSeerX!

A Data Mining and CIDF Based Approach for Detecting Novel and Distributed Intrusions (2000)  (Make Corrections)  (9 citations)
Wenke Lee, Rahul A. Nimbalkar, Kam K. Yee, Sunil B. Patil, Pragneshkumar H. Desai, Thuan T. Tran, Salvatore J. Stolfo
Lecture Notes in Computer Science



  Home/Search   Context   Related

 
View or download:
ncsu.edu/faculty/lee/p...lee_raid_00.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  ncsu.edu/faculty/l...publications (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: . As the recent distributed Denial-of-Service (DDOS) attacks on several major Internet sites have shown us, no open computer network is immune from intrusions. Furthermore, intrusion detection systems (IDSs) need to be updated timely whenever a novel intrusion surfaces; and geographically distributed IDSs need to cooperate to detect distributed and coordinated intrusions. In this paper, we describe an experimental system, based on the Common Intrusion Detection Framework (CIDF), where... (Update)

Context of citations to this paper:   More

.... rule induction [14, 15, 16] artificial) neural networks [17, 18, 19] fuzzy set theory [20] classical machine learning algorithms [21, 22], artificial immune systems [23, 24] signal processing methods [25] and temporal sequence learning [26, 27] A challenge that all...

...which IDS s can be compared. A number of studies based their research on this data set which in theory allows them to compare results [8,9,15]. Yet, given that problems were identified in the Lincoln data [18] relying on it as a data source may not be desirable for ID...

Cited by:   More
A Multiagent Approach to Outbound Intrusion Detection - Mandujano (2004)   (Correct)
Distributed Intrusion Detection Systems: A Computational.. - Ajith Abraham And (2005)   (Correct)
Analysis of Distributed Intrusion Detection Systems.. - Burroughs, Wilson.. (2002)   (Correct)

Active bibliography (related documents):   More   All
0.3:   A Data Mining Framework for Building Intrusion Detection Models - Lee, Stolfo, Mok (1999)   (Correct)
0.2:   The Effect of Identifying Vulnerabilities and Patching.. - Lippmann, Webster.. (2002)   (Correct)
0.2:   SIFF: A Stateless Internet Flow Filter to Mitigate DDoS.. - Yaar, Perrig, Song (2004)   (Correct)

System load high. Please wait...
Timeout. Please try your query later.
Similar documents based on text:   More   All
1.0:   Modeling Requests among Cooperating Intrusion Detection Systems - Ning, Wang, Jajodia (2000)   (Correct)
0.9:   Using Artificial Anomalies to Detect Unknown and Known.. - Fan, Miller, Stolfo (2001)   (Correct)
0.6:   Correlating Alerts Using Prerequisites of Intrusions - Ning, Reeves, Cui (2001)   (Correct)

Related documents from co-citation:   More   All
5:   Computer Security Threat Monitoring and Surveillance (context) - Anderson - 1980
5:   Temporal sequence learning and data reduction for anomaly detection - Lane, Brodie - 1998
5:   Design and Implementation of a Scalable Intrusion Detection System for the Prote.. - Jou, Gong et al. - 2000

BibTeX entry:   (Update)

W. Lee, R. Nimbalkar, K. Yee, S. Patil, P. Desai, T. Tran, and S. J. Stolfo. A data mining and CIDF based approach for detecting novel and distributed intrusions. In Proceedings of the 3rd International Workshop on Recent Advances in Intrusion Detection (RAID 2000), October 2000. to appear. http://citeseer.ist.psu.edu/article/lee00data.html   More

@article{ lee00data,
    author = "Wenke Lee and Rahul A. Nimbalkar and Kam K. Yee and Sunil B. Patil and Pragneshkumar H. Desai and Thuan T. Tran and Salvatore J. Stolfo",
    title = "A Data Mining and {CIDF} Based Approach for Detecting Novel and Distributed Intrusions",
    journal = "Lecture Notes in Computer Science",
    volume = "1907",
    pages = "49--??",
    year = "2000",
    url = "citeseer.ist.psu.edu/article/lee00data.html" }
Citations (may not include all citations):
248   Fast effective rule induction - Cohen - 1995
132   EMERALD: Event monitoring enabling responses to anomalous li.. - Porras, Neumann - 1997
123   Bro: A system for detecting network intruders in real-time - Paxson - 1998
105   State transition analysis: A rulebased intrusion detection a.. - Ilgun, Kemmerer et al. - 1995
70   A data mining framework for building intrusion detection mod.. - Lee, Stolfo et al. - 1999
58   available via anonymous ftp to ftp (context) - Jacobson, Leres et al. - 1989
56   A real-time intrusion detection expert system (context) - Lunt, Tamaru et al. - 1992
35   Mining audit data to build intrusion detection models - Lee, Stolfo et al. - 1998
32   A software architecture to support misuse intrusion detectio.. - Kumar, Spafford - 1995
30   The architecture of a network level intrusion detection syst.. (context) - Heady, Luger et al. - 1990
17   A Data Mining Framework for Constructing Features and Models.. - Lee - 1999
15   Network flight recorder (context) - Recorder - 1997
10   Blueprint for a computer immune system (context) - Kephart, Sorkin et al. - 1997
8   Common intrusion detection framework (context) - Stainford-Chen
5   Internet-Draft draft-rivest-sexp (context) - Rivest - 1997
4   Distributed denial of service (context) - Dittrich
1   The common intrusion specification language: A retrospective (context) - Tung - 2000



The graph only includes citing articles where the year of publication is known.


Documents on the same site (http://www.csc.ncsu.edu/faculty/lee/publications.html):   More
Learning Patterns from Unix Process Execution Traces for.. - Lee, Stolfo (1997)   (Correct)
Interfacing Oz with the PCTE OMS: A Case Study of Integrating a .. - Lee, Kaiser   (Correct)
Mining Audit Data to Build Intrusion Detection Models - Lee, Stolfo, Mok (1998)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC