Skip to main content
Article
Anomaly payload signature generation system based on efficient tokenization methodology
International Journal on Communications Antenna and Propagation
  • Monther Aldwairi, Jordan University of Science and Technology
  • Wail Mardini, Jordan University of Science and Technology
  • Alaa Alhowaide, Jordan University of Science and Technology
Document Type
Article
Publication Date
10-1-2018
Abstract

© 2018 Praise Worthy Prize S.r.l. All rights reserved. Signature-based intrusion detection systems are widely used as an efficient network security control. Unfortunately, security experts manually craft attack signatures after capturing and analyzing the exploit code. Therefore, those systems are only able to detect known attacks. In this paper, we propose a new automated and content-based signature generation system that generates anomaly profiles to detect new and previously unknown attacks and worms. The proposed system, denoted SCANS, uses a natural tokenization method that speeds up the signature generation process by producing a fewer number of substrings. In this system, we propose a new stop character technique that will help to overcome signatures’ substrings granularity limitations of the old stop word techniques. In addition, SCANS introduces an improved normalized binary detection model specifically tailored for attacks detection. Experimental testing using DARPA IDS dataset shows a 95% malicious packets detection rate for port 23, with specificity of 88.4% and 94.6% for ports 21 and 25, respectively.

Publisher
Praise Worthy Prize S.r.l
Disciplines
Keywords
  • Anomaly detection,
  • Natural tokenization,
  • Signature generation
Scopus ID
85061724678
Indexed in Scopus
Yes
Open Access
No
https://doi.org/10.15866/irecap.v8i5.12794
Citation Information
Monther Aldwairi, Wail Mardini and Alaa Alhowaide. "Anomaly payload signature generation system based on efficient tokenization methodology" International Journal on Communications Antenna and Propagation Vol. 8 Iss. 5 (2018) p. 421 - 429 ISSN: <a href="https://v2.sherpa.ac.uk/id/publication/issn/2039-5086" target="_blank">2039-5086</a>
Available at: http://works.bepress.com/monther-aldwairi/41/