MINDS: A New Approach to the Information Security Process

Abstract : This paper describes the work the University of Minnesota is doing with the U.S. Army Research Laboratory to advance the state-of-the-art in network intrusion detection. The Minnesota Network Intrusion Detection System (MINDS) is a data mining based system for detecting unusual network behavior, and emerging cyber threats. MINDS is enjoying great operational success in the ARL's Interrogator information assurance architecture and at the University of Minnesota. MINDS routinely detects brand new attacks and other malicious behaviors which could not have been detected by signature based systems. In addition to detecting new attacks MINDS is very effective at discovering rogue communication channels and the exfiltration of data that are very difficult to identify with other tools.