Dutch researchers develop self-learning security system for computer networks

June 30, 2009

(PhysOrg.com) -- Cyber attacks on computer networks are becoming increasingly commonplace. To counter the threat, they are protected by so-called network intrusion detection systems. But these fail to identify some attacks, or do not spot them until it is too late.

To improve matters, Damiano Bolzoni of the University of Twente, The Netherlands, has developed a system which paves the way for a new generation of network security. This forms the subject of his doctorate, awarded by the Faculty of Electrical Engineering, Mathematics and Computer Science on 25 June.

A network intrusion detection system (NIDS) is like a kind of virus scanner, but for an entire network rather than a single computer. There are two types. The first draws upon a database of all known attacks, such as those attempted by . It works by recognizing the ‘signatures’ of methods previously used. But this means that it will not at first spot a new and as yet unknown method.

The second kind of NIDS uses anomaly detection. In other words, it learns how the network is normally used and if it spots a deviation from this standard pattern it will alert the system administrator so that the suspected attack can be investigated. In practice, however, this type is not widely used because no really good systems are yet available commercially.

Bolzoni has been trying to change that by developing a new anomaly detection NIDS, which he has named SilentDefense. His system is based upon self-learning algorithms, which make it far more accurate than existing systems of this kind. Moreover, the chance of ‘false positive’ alerts is about 1000 times lower than in the systems currently available.

The system is now being further developed by SecurityMatters, the company recently founded by Bolzoni and fellow researchers Emmanuele Zambon and Sandro Etalle. They expect to launch SilentDefense commercially in mid-2010.

In Bolzoni’s view, the ideal NIDS is not of one type or the other but combines the two. For that to be possible, however, a good system based upon anomaly detection first needs to become available.

Provided by University of Twente (news : web)


   
Rate this story - 3 /5 (1 vote)


June 30, 2009 all stories

Comments: 0

3 /5 (1 vote)

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Computer 5V or 0V output to Sensaphone Express II
    created Feb 04, 2010
  • Ti-89 ROM Image
    created Jan 29, 2010
  • TV ads
    created Jan 29, 2010
  • Apple introduces latest iNonsense
    created Jan 27, 2010
  • More from Physics Forums - Computing & Technology

Other News

A general view of the arrival area of the Whistler Creek Alpine Skiing venue

Google Maps climbs to Olympic peaks

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

Google sent snowmobiles rigged with cameras into Canadian mountains so folks snug and warm at home will get views of slopes at the Winter Olympic Games kicking off on Friday.


The power of 'random'

The power of 'random': 'Seemingly loopy' technique could dramatically improve communications networks

Technology / Computer Sciences

created 11 hours ago | popularity 4.8 / 5 (6) | comments 5 | with audio podcast

A radical new approach to the design of communications networks, called "network coding," promises to make Internet file sharing faster, streaming video more reliable, and cell-phone reception better -- among ...


Warner CEO sees e-book 'fracas' as helping music

Technology / Business

created 2 hours ago | popularity not rated yet | comments 0

(AP) -- The head of Warner Music Group expressed hope on Tuesday that the recent "fracas" over the price of e-books would help give content creators such as his company more pricing power over device makers.


'Revolutionary' water treatment units on their way to Afghanistan

Technology / Engineering

created 5 hours ago | popularity 5 / 5 (3) | comments 1 | with audio podcast

The United States Army has taken delivery of the first two units of a "revolutionary" waste-water treatment system that will clean putrid water within 24 hours and leave no toxic by-products, according to scientists at Sam ...


Imec and Holst Centre achieve breakthrough in battery-less radios

Imec achieves breakthrough in battery-less radios

Technology / Semiconductors

created 6 hours ago | popularity 5 / 5 (5) | comments 0 | with audio podcast

At today's International Solid State Circuit Conference, Imec and Holst Centre report a 2.4GHz/915MHz wake-up receiver which consumes only 51µW power. This record low power achievement opens the door to battery-less ...