We present an approach to the problem of detecting intru- sions in computer systems through the use behavioral data produced by users during their normal login sessions. In fact, attacks may be detected by observing abnormal behavior, and the technique we use consists in associating to each system user a classifier made with relational decision trees that will label login sessions as "legals" or as "intrusions". We perform an experimentation for 10 users, based on their normal work, gathered during a period of three months. We obtain a correct user recog- nition of 90%, using an independent test set. The test set consists of new, previously unseen sessions for the users considered during training, as well as sessions from users not available during the training phase. The obtained performance is comparable with previous studies, but (1) we do not use information that may effect user privacy and (2) we do not bother the users with questions.

Intrusion Detection through Behavioral Data

GUNETTI, Daniele;RUFFO, Giancarlo Francesco
1999-01-01

Abstract

We present an approach to the problem of detecting intru- sions in computer systems through the use behavioral data produced by users during their normal login sessions. In fact, attacks may be detected by observing abnormal behavior, and the technique we use consists in associating to each system user a classifier made with relational decision trees that will label login sessions as "legals" or as "intrusions". We perform an experimentation for 10 users, based on their normal work, gathered during a period of three months. We obtain a correct user recog- nition of 90%, using an independent test set. The test set consists of new, previously unseen sessions for the users considered during training, as well as sessions from users not available during the training phase. The obtained performance is comparable with previous studies, but (1) we do not use information that may effect user privacy and (2) we do not bother the users with questions.
1999
Inglese
contributo
third symposium on Intelligent Data Analysis
Amsterdam
August 1999
Internazionale
proc. of the third symposium on Intelligent Data Analysis
Sì, ma tipo non specificato
Springer Verlag
Berlin
GERMANIA
LNCS 1642
383
394
Computer Security; Intrusion Detection; Behavioura Data
2
info:eu-repo/semantics/conferenceObject
04-CONTRIBUTO IN ATTI DI CONVEGNO::04A-Conference paper in volume
GUNETTI D.; G. RUFFO
273
none
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2318/19866
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 11
  • ???jsp.display-item.citation.isi??? 6
social impact