IDS mailing list archives

Re: How do behavioral/anomaly detection systems learn?


From: Jason Anderson <janderson () lancope com>
Date: 6 Feb 2004 13:39:07 -0000

In-Reply-To: <00b501c3ebaf$d82eb650$6401a8c0@LAPTOP>

Sasha,

when looking at how behavioral systems learn, it's important to first consider what those systems track and report on. 

A network-based behavioral system is primarily looking at activity levels and the services provided and utilized by 
hosts on the network. These core data values can be observed, and a baseline developed for "normal" behavior. The 
administrator can then use the observed values as a default policy, or can use that information to further refine 
allowed behavior for their network.

For example, after a period of tuning you will have observed which devices are active on your network, who's offering 
http, smtp, and other services, what a normal traffic volume is for each of those systems, and you will subsequently 
have a reasonable picture of normal operations. Then, whenever a system starts to exceed that baseline, or offer 
services for the first time, it can be noticed and reported by the system.

One typical limitation of a pure behavior-based approach is that it is generally incapable of determining the 
difference between what's bad and what's good. An additional layer of intelligence must be added to prevent automatic 
learning of bad behavior, a common problem associated with this type of approach.

For example, immediately upon installation, Lancope's StealthWatch applies a series of algorithms to network flows 
observed on the wire. These proprietary, flow-based algorithms help detect systems that are broken or compromised at 
the time of install and prevent the tuning of bad behavior into the baseline profile.

Thus, the tuning process not only includes establishing a baseline, but also identifying existing problems on the 
network so that they can be dealt with and not "tuned-in".

Jason

--

Jason Anderson - Product Manager, Lancope - (770) 225-6519
Lancope: Security through Network Intelligence http://www.lancope.com


From: "Sasha Romanosky" <sasha_romanosky () yahoo com>
To: <focus-ids () securityfocus com>
Subject: How do behavioral/anomaly detection systems learn?
Date: Wed, 4 Feb 2004 22:18:16 -0800
Greetings, 

In regards to "behavioral" or "anomaly" detection systems vs. pure
signature-based detection systems, I'm trying to understand how these
behavioral technologies differentiate "good" traffic from "bad" traffic.
I don't want to get into which is better, because they both have their
place, of course. What I'm trying to understand is how these behavioral
systems work, or "learn". 

I have seen that this technique is not unique to intrusion detection
systems, but also appears in application firewalls (e.g. Teros) and
email virus scanners (e.g. using bayesian filtering). 

With some products, I see that you configure them with specific rules,
tailored to your particular environment, and with other products, you
just point it to the network and it creates a profile all by itself. 

Does this simply amount to another form of signature system, just with
more intelligent signatures? Or is it more complex than this?.

Any references (whitepapers, archives, sites, etc) explaining this
learning would be most appreciated.


Cheers,
Sasha Romanosky


------------------------------------------------------------------------

---------------------------------------------------------------------------
---------------------------------------------------------------------------


Current thread: