Network Security White Papers

POSEIDON: A 2-Tier Anomaly-Based Network Intrusion Detection System

Overview Intrusion Detection Systems (IDSs) were introduced by Anderson and formalized later by Denning. Nowadays, there exist two main types of network intrusion detection methods: anomaly-based and signature-based. In signature-based methods, a characteristic trait of the intrusion is developed off-line, and then loaded in the intrusion database before the system can begin to detect this particular intrusion. This paper presents POSEIDON, a new anomaly-based network intrusion detection system. POSEIDON is payload-based, and has two-tier architecture the first stage consists of a Self-Organizing Map, while the second one is a modified PAYL system.

Further White Paper Details
PublisherInstitute of Electrical and Electronics Engineers File FormatPDF
Date PublishedApril 2006
FormatWhite Papers   
Topics

Quick Sitemap Links: