Skip to main navigation Skip to search Skip to main content

Human interface for cyber security anomaly detection systems

  • Denis Todd Vollmer
  • , Milos Manic

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Low-level network traffic information is often times beyond the understanding of common system operators (byte counts, port numbers, packet data, etc.). However, anomaly based Intrusion Detection Systems (IDS) often provide such low-level, difficult to comprehend information. This paper details a Human Interface for Security Awareness (HISA) algorithm for interpreting cyber incident information to human operators from anomaly based intrusion detections systems. A similarity algorithm mapping anomaly results to signature based intrusion system rules is developed. Categorizations of attacks found in rules created for the Snort intrusion system were used as a basis of information to present to the user. A proof of concept system was developed using Perl native functions and custom modules. Testing with generated ICMP packets resulted in an identification accuracy of 60% proving the efficacy of the presented HISA algorithm.

Original languageEnglish
Title of host publicationProceedings - 2009 2nd Conference on Human System Interactions, HSI '09
Pages654-659
Number of pages6
DOIs
StatePublished - 2009
Externally publishedYes
Event2009 2nd Conference on Human System Interactions, HSI '09 - Catania, Italy
Duration: May 21 2009May 23 2009

Publication series

NameProceedings - 2009 2nd Conference on Human System Interactions, HSI '09

Conference

Conference2009 2nd Conference on Human System Interactions, HSI '09
Country/TerritoryItaly
CityCatania
Period05/21/0905/23/09

Keywords

  • Command and control systems
  • Site security monitoring

Fingerprint

Dive into the research topics of 'Human interface for cyber security anomaly detection systems'. Together they form a unique fingerprint.

Cite this