Self-learning security system for computer networks

Jul 09, 2009

Cyber attacks on computer networks are becoming increasingly commonplace. To counter the threat, they are protected by so-called network intrusion detection systems. But these fail to identify some attacks, or do not spot them until it is too late. To improve matters, Damiano Bolzoni of the University of Twente (The Netherlands) has developed a system which paves the way for a new generation of network security. This forms the subject of his doctorate, awarded by the Faculty of Electrical Engineering, Mathematics and Computer Science on 25 June.

A network intrusion detection system (NIDS) is like a kind of virus scanner, but for an entire network rather than a single computer. There are two types. The first draws upon a database of all known attacks, such as those attempted by . It works by recognizing the ‘signatures’ of methods previously used. But this means that it will not at first spot a new and as yet unknown method.

The second kind of NIDS uses anomaly detection. In other words, it learns how the is normally used and if it spots a deviation from this standard pattern it will alert the system administrator so that the suspected attack can be investigated. In practice, however, this type is not widely used because no really good systems are yet available commercially.

Bolzoni has been trying to change that by developing a new anomaly detection NIDS, which he has named SilentDefense. His system is based upon self-learning algorithms, which make it far more accurate than existing systems of this kind. Moreover, the chance of ‘false positive’ alerts is about 1000 times lower than in the systems currently available.

The system is now being further developed by SecurityMatters, the company recently founded by Bolzoni and fellow researchers Emmanuele Zambon and Sandro Etalle. They expect to launch SilentDefense commercially in mid-2010.

In Bolzoni’s view, the ideal NIDS is not of one type or the other but combines the two. For that to be possible, however, a good system based upon anomaly detection first needs to become available.

Provided by University of Twente (news : web)

Explore further: Sensitive bomb detector to rove in search of danger

add to favorites email to friend print save as pdf

Related Stories

The phony goat gets the worm

Mar 28, 2006

IBM researchers have designed a new way to detect and thwart attacks on computer networks. Code named "Billy Goat," the intrusion detection tool provides both early detection of worm attacks and fewer false alarms than other ...

New intrusion tolerance software fortifies server secrurity

Jun 16, 2008

In spite of increased focus and large investments in computer security, critical infrastructure systems remain vulnerable to attacks, says Arun Sood, professor of computer science at George Mason University. The increasing ...

Recommended for you

Sensitive bomb detector to rove in search of danger

10 hours ago

European researchers have developed and tested a light-weight device capable of detecting extremely minute quantities of explosives from up to 20 metres away, providing an invaluable law-enforcement tool ...

How soon could car seats enter the 3-D comfort zone?

May 23, 2013

New 3D textiles made of recyclable polyester fibres could contribute help cars be easier to recycle. But recycling technology has yet to progress in separating seat material from other car components.

NASA: Austin, calling Austin. 3-D pizzas to go

May 22, 2013

(Phys.org) —The idea of living with 3-D printed food is neither unthinkable nor new; designers and futurists have been looking to 3-D printing as food's next frontier. In 2012, there was news that the Thiel ...

User comments : 0

More news stories

Google eyes emerging markets networks

Google has become deeply involved in a series of projects to build and operate wireless networks in emerging markets including sub-Saharan Africa and Southeast Asia, a report said Friday.

Facial-recognition technology proves its mettle

(Phys.org) —In a study that evaluated some of the latest in automatic facial recognition technology, researchers at Michigan State University were able to quickly identify one of the Boston Marathon bombing ...

Drones may violate international law

(Phys.org) —As President Obama gives a speech on national security—including defending U.S. use of drones to combat terrorism—Leila Sadat, JD, international law expert and professor of law at Washington University in ...

Galaxies fed by funnels of fuel

(Phys.org) —Computer simulations of galaxies growing over billions of years have revealed a likely scenario for how they feed: a cosmic version of swirly straws.