Enkhbold Chimetseren, Keisuke Iwai, Hidema Tanaka, T. Kurokawa
{"title":"A study of IDS using Discrete Fourier Transform","authors":"Enkhbold Chimetseren, Keisuke Iwai, Hidema Tanaka, T. Kurokawa","doi":"10.1109/ATC.2014.7043432","DOIUrl":null,"url":null,"abstract":"Intrusion Detection System (IDS) detects attacks using pattern files which are known as “signature”. Effectiveness of detection depends on the kind of signature. In this paper, we propose a signature generation method using Discrete Fourier Transform. Our method regards payload between client and server as discrete waveform. Regarding normal communication spectrum as noise, we can clarify the characteristics of attack sessions. From the viewpoint of spectrum analysis, our method detects attack sessions. Furthermore, it has dynamic analysis features like anomaly type of IDS and will be able to detect unknown attack session. Our proposal method simulated using a Kyoto2006+ data set which is currently used as an intrusion detection evaluation. As the result, we have 5% of false positives for detecting attacks.","PeriodicalId":333572,"journal":{"name":"2014 International Conference on Advanced Technologies for Communications (ATC 2014)","volume":"93 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Conference on Advanced Technologies for Communications (ATC 2014)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ATC.2014.7043432","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Intrusion Detection System (IDS) detects attacks using pattern files which are known as “signature”. Effectiveness of detection depends on the kind of signature. In this paper, we propose a signature generation method using Discrete Fourier Transform. Our method regards payload between client and server as discrete waveform. Regarding normal communication spectrum as noise, we can clarify the characteristics of attack sessions. From the viewpoint of spectrum analysis, our method detects attack sessions. Furthermore, it has dynamic analysis features like anomaly type of IDS and will be able to detect unknown attack session. Our proposal method simulated using a Kyoto2006+ data set which is currently used as an intrusion detection evaluation. As the result, we have 5% of false positives for detecting attacks.