Forum for Science, Industry and Business

Sponsored by:     3M 
Search our Site:

 

To Detect Cyberattacks, New Software System Developed at UB Profiles ’Normal’ Computer Habits

11.10.2002


An early version of a new software system developed by University at Buffalo researchers that detects cyberattacks while they are in progress by drawing highly personalized profiles of users has proven successful 94 percent of the time in simulated attacks.



The "user-level anomaly detection system" was described here today (Oct. 10, 2002) at the military communications conference known as MILCOM 2002.

"We have developed a new paradigm, proactively encapsulating user intent where you basically generate a profile for every single user in the system where security is a major concern," said Shambhu Upadhyaya, Ph.D., associate professor of computer science and engineering at UB and co-author of the paper.


In addition to the paper presentation, MILCOM invited Upadhyaya to give a half-day tutorial on the new intrusion detection system at the meeting.

Upadhyaya directs UB’s Center of Excellence in Information Systems Assurance Research and Education, one of 36 in the U.S. chosen by the National Security Agency to develop new programs to conduct research and train students to protect the nation’s information technology systems from cyberterrorism.

The new UB intrusion detection system is being developed for application in highly secure facilities, such as those in the military.

"Existing approaches look at a past record of computer activity because those systems produce audits of activity for every user," he explained. "Our methodology is a marriage of two known techniques: misuse and anomaly detection. We use an assertion/rule-based approach to precisely capture the initial bracket of activity and then fine-tune this profile to reflect ongoing activity, making highly personalized and accurate profiles possible.

"Also, since users are being constantly monitored, this system can detect intrusions or attacks on-the-fly."

The UB system generates a user profile according to data about standard operations and commands that each user follows to carry out specific tasks.

The system is designed to detect significant deviations from procedures followed by normal users.

While some commercially available computer security packages already feature user-profiling, Upadhyaya noted that they are based on "low-level" methods -- meaning they seek out deviations on the basis of huge amounts of data, so they end up creating many false alarms.

"User modeling is computationally hard," said Upadhyaya. "Since many of these existing systems treat this problem purely statistically, any deviation from the norm is signaled as an anomaly, but it is often the case that an intrusion has not occurred.

"It’s a nuisance because an alarm can go off as often as every five minutes," he said.

By contrast, the system he developed with co-authors Rankumar Chinchani, a doctoral candidate in the UB Department of Computer Science and Engineering, and Kevin Kwiat of the Air Force Research Laboratory in Rome, N.Y., is based on the idea that the computation habits of normal users generally are well-defined and that he or she will work within those bounds.

"The normal behavior of computer users has been very well characterized," said Upadhyaya. "Normal users stick within well-defined parameters. Intruders or hackers, on the other hand, will not be able to carry out their intended operations within such well-defined parameters, and so will make the scope of his or her activities overly permissive," said Upadhyaya. "Our system is based on detecting that kind of behavior."

The key to the UB system’s success and its "scalable" feature is that its monitoring system operates at a high level, examining commands that users execute to perform certain operations. This is in contrast to the low-level monitoring that many existing packages perform, which examine commands as basic as the ones and zeroes of which email messages are composed.

"Our system is looking for a sequence of operations that falls within certain ’normal’ parameters," he explained.

"For example, if you want to make a document, you do certain things in a certain order, you create the document, you use a word processing program, you may run Spellcheck. Our system knows what to look for in the normal sequence that is necessary to accomplish this job. Any deviations from that are assumed to be potential cyberattacks."

The work was funded by the Air Force Research Laboratory in Rome, N.Y.

Ellen Goldbaum | EurekAlert!
Further information:
http://www.buffalo.edu/

More articles from Information Technology:

nachricht Multifunctional e-glasses monitor health, protect eyes, control video game
28.05.2020 | American Chemical Society

nachricht Researchers incorporate computer vision and uncertainty into AI for robotic prosthetics
28.05.2020 | North Carolina State University

All articles from Information Technology >>>

The most recent press releases about innovation >>>

Die letzten 5 Focus-News des innovations-reports im Überblick:

Im Focus: Biotechnology: Triggered by light, a novel way to switch on an enzyme

In living cells, enzymes drive biochemical metabolic processes enabling reactions to take place efficiently. It is this very ability which allows them to be used as catalysts in biotechnology, for example to create chemical products such as pharmaceutics. Researchers now identified an enzyme that, when illuminated with blue light, becomes catalytically active and initiates a reaction that was previously unknown in enzymatics. The study was published in "Nature Communications".

Enzymes: they are the central drivers for biochemical metabolic processes in every living cell, enabling reactions to take place efficiently. It is this very...

Im Focus: New double-contrast technique picks up small tumors on MRI

Early detection of tumors is extremely important in treating cancer. A new technique developed by researchers at the University of California, Davis offers a significant advance in using magnetic resonance imaging to pick out even very small tumors from normal tissue. The work is published May 25 in the journal Nature Nanotechnology.

researchers at the University of California, Davis offers a significant advance in using magnetic resonance imaging to pick out even very small tumors from...

Im Focus: I-call - When microimplants communicate with each other / Innovation driver digitization - "Smart Health“

Microelectronics as a key technology enables numerous innovations in the field of intelligent medical technology. The Fraunhofer Institute for Biomedical Engineering IBMT coordinates the BMBF cooperative project "I-call" realizing the first electronic system for ultrasound-based, safe and interference-resistant data transmission between implants in the human body.

When microelectronic systems are used for medical applications, they have to meet high requirements in terms of biocompatibility, reliability, energy...

Im Focus: When predictions of theoretical chemists become reality

Thomas Heine, Professor of Theoretical Chemistry at TU Dresden, together with his team, first predicted a topological 2D polymer in 2019. Only one year later, an international team led by Italian researchers was able to synthesize these materials and experimentally prove their topological properties. For the renowned journal Nature Materials, this was the occasion to invite Thomas Heine to a News and Views article, which was published this week. Under the title "Making 2D Topological Polymers a reality" Prof. Heine describes how his theory became a reality.

Ultrathin materials are extremely interesting as building blocks for next generation nano electronic devices, as it is much easier to make circuits and other...

Im Focus: Rolling into the deep

Scientists took a leukocyte as the blueprint and developed a microrobot that has the size, shape and moving capabilities of a white blood cell. Simulating a blood vessel in a laboratory setting, they succeeded in magnetically navigating the ball-shaped microroller through this dynamic and dense environment. The drug-delivery vehicle withstood the simulated blood flow, pushing the developments in targeted drug delivery a step further: inside the body, there is no better access route to all tissues and organs than the circulatory system. A robot that could actually travel through this finely woven web would revolutionize the minimally-invasive treatment of illnesses.

A team of scientists from the Max Planck Institute for Intelligent Systems (MPI-IS) in Stuttgart invented a tiny microrobot that resembles a white blood cell...

All Focus news of the innovation-report >>>

Anzeige

Anzeige

VideoLinks
Industry & Economy
Event News

Dresden Nexus Conference 2020: Same Time, Virtual Format, Registration Opened

19.05.2020 | Event News

Aachen Machine Tool Colloquium AWK'21 will take place on June 10 and 11, 2021

07.04.2020 | Event News

International Coral Reef Symposium in Bremen Postponed by a Year

06.04.2020 | Event News

 
Latest News

Black nitrogen: Bayreuth researchers discover new high-pressure material and solve a puzzle of the periodic table

29.05.2020 | Materials Sciences

Argonne researchers create active material out of microscopic spinning particles

29.05.2020 | Materials Sciences

Smart windows that self-illuminate on rainy days

29.05.2020 | Power and Electrical Engineering

VideoLinks
Science & Research
Overview of more VideoLinks >>>