A cooperative connectionist IDS model to identify independent anomalous SNMP situations

Abstract

This research approaches the anomalous situations detection issue from a pattern recognition point of view, where a connectionist model is applied to identify user behavior patterns. The aim of this multidisciplinary research is the design of a system capable of detecting anomalous situations for a computer network. The connectionist architecture used here has never been applied to the Intrusion Detection (ID) and network security fields before this research. This work line demonstrates that connectionist models are capable of satisfying the requirements and dynamic features of the ID problem. By exploiting the strengths of neural networks in recognition, classification and generalization, this work illustrates the effectiveness of these techniques to the ID field. The presented Intrusion Detection System (IDS) is used as a method to investigate the traffic that travels along the analysed network, detecting SNMP (Simple Network Management Protocol) anomalous traffic patterns. It is also shown how the system is capable of detecting independent SNMP anomalous situations. It helps network administrators to decide if these anomalous situations are real intrusions or not.

Extracted Key Phrases

5 Figures and Tables

Cite this paper

@inproceedings{Herrero2005ACC, title={A cooperative connectionist IDS model to identify independent anomalous SNMP situations}, author={{\'A}lvaro Herrero and Emilio Corchado and Jos{\'e} Manuel S{\'a}iz}, year={2005} }