首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >DDSGA: A Data-Driven Semi-Global Alignment Approach for Detecting Masquerade Attacks
【24h】

DDSGA: A Data-Driven Semi-Global Alignment Approach for Detecting Masquerade Attacks

机译:DDSGA:一种数据驱动的半全局对准方法,用于检测化装舞会的攻击

获取原文
获取原文并翻译 | 示例
           

摘要

A masquerade attacker impersonates a legal user to utilize the user services and privileges. The semi-global alignment algorithm (SGA) is one of the most effective and efficient techniques to detect these attacks but it has not reached yet the accuracy and performance required by large scale, multiuser systems. To improve both the effectiveness and the performances of this algorithm, we propose the Data-Driven Semi-Global Alignment, DDSGA approach. From the security effectiveness view point, DDSGA improves the scoring systems by adopting distinct alignment parameters for each user. Furthermore, it tolerates small mutations in user command sequences by allowing small changes in the low-level representation of the commands functionality. It also adapts to changes in the user behaviour by updating the signature of a user according to its current behaviour. To optimize the runtime overhead, DDSGA minimizes the alignment overhead and parallelizes the detection and the update. After describing the DDSGA phases, we present the experimental results that show that DDSGA achieves a high hit ratio of 88.4 percent with a low false positive rate of 1.7 percent. It improves the hit ratio of the enhanced SGA by about 21.9 percent and reduces Maxion-Townsend cost by 22.5 percent. Hence, DDSGA results in improving both the hit ratio and false positive rates with an acceptable computational overhead.
机译:假冒伪装的攻击者冒充合法用户以利用用户服务和特权。半全局对齐算法(SGA)是检测这些攻击的最有效的技术之一,但尚未达到大规模多用户系统所需的准确性和性能。为了提高该算法的有效性和性能,我们提出了数据驱动的半全局比对DDSGA方法。从安全有效性的角度来看,DDSGA通过为每个用户采用不同的对齐参数来改进评分系统。此外,通过允许对命令功能的低级表示进行小的更改,它可以容忍用户命令序列中的小变化。它还通过根据用户的当前行为更新其签名来适应用户行为的变化。为了优化运行时开销,DDSGA最小化了对齐开销,并使检测和更新并行化。在描述了DDSGA阶段之后,我们提供了实验结果,该结果表明DDSGA实现了88.4%的高命中率和1.7%的低误报率。它将增强型SGA的命中率提高了约21.9%,并将Maxion-Townsend成本降低了22.5%。因此,DDSGA可以提高命中率和误报率,并具有可接受的计算开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号