IP Spoofing Detection Approach(ISDA) for network Intrusion detection system

被引:0
|
作者
Song, Sui [1 ]
Manikopoulos, C. N. [1 ]
机构
[1] New Jersey Inst Technol, ECE Dept, Newark, NJ 07102 USA
关键词
flow; field aggregation schemes; prefix aggregation scheme; flow aggregation scheme; neural network classifier; Flow-based Network Intrusion Detection System;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A new approach for detecting spoofed IP level, called IP Spoofing Detection Approach (ISDA), is proposed. The purpose of this approach is maximally to keep effective parts and remove forged parts of Source IP addresses under flooding attacks and dynamically configure flow aggregation scheme for flow-based network Intrusion detection to build the most effective intrusion detection approach. Our work concentrates on developing an overall framework, which includes building flow aggregation schemes for Flow-based Network Intrusion Detection System (FNIDS), detecting IP address spoofing level and using Fuzzy logic method automatically to activate the most appropriate flow aggregation scheme. Finally, the performance of applying our proposed architecture against flooding DDOS attacks is evaluated by using DARPA 98 data. Results show the significant improvement for FNIDS after applying the IP address spoofing detection algorithms.
引用
收藏
页码:355 / 358
页数:4
相关论文
共 50 条
  • [1] ADES approach to Intrusion Detection System for ARP Spoofing Attacks
    Neminath, H.
    Biswas, S.
    Roopa, S.
    Ratti, R.
    Nandi, S.
    Barbhuiya, F. A.
    Sur, A.
    Ramachandran, V.
    18TH MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION, 2010, : 695 - 700
  • [2] Network intrusion detection system: A machine learning approach
    Panda, Mrutyunjaya
    Abraham, Ajith
    Das, Swagatam
    Patra, Manas Ranjan
    INTELLIGENT DECISION TECHNOLOGIES-NETHERLANDS, 2011, 5 (04): : 347 - 356
  • [3] An Improved CNN Approach for Network Intrusion Detection System
    Hu, Jianwei
    Liu, Chenshuo
    Cui, Yanpeng
    International Journal of Network Security, 2021, 23 (04) : 569 - 575
  • [4] Bandwidth Spoofing and Intrusion Detection System for Multistage 5G Wireless Communication Network
    Gupta, Akhil
    Jha, Rakesh Kumar
    Gandotra, Pimmy
    Jain, Sanjeev
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2018, 67 (01) : 618 - 632
  • [5] Distributed Network Intrusion Detection System: An Artificial Immune System Approach
    Igbe, Obinna
    Darwish, Ihab
    Saadawi, Tarek
    2016 IEEE FIRST INTERNATIONAL CONFERENCE ON CONNECTED HEALTH: APPLICATIONS, SYSTEMS AND ENGINEERING TECHNOLOGIES (CHASE), 2016, : 101 - 106
  • [6] Modified Apriori Approach for Evade Network Intrusion Detection System
    Lahoti, Laxmi
    Chandankhede, Chaitali
    Mukhopadhyay, Debajyoti
    2014 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY (ICIT), 2014, : 374 - 378
  • [7] A Novel Approach for the Design of Network Intrusion Detection System(NIDS)
    Jadhav, Ambarish
    Jadhav, Avinash
    Jadhav, Pradeep
    Kulkarni, Prakash
    2013 INTERNATIONAL CONFERENCE ON SENSOR NETWORK SECURITY TECHNOLOGY AND PRIVACY COMMUNICATION SYSTEM (SNS & PCS), 2013, : 22 - 27
  • [8] Combinational Feature Selection Approach for Network Intrusion Detection System
    Garg, Tanya
    Kumar, Yogesh
    2014 INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (PDGC), 2014, : 82 - 87
  • [9] A Sequential Approach to Network Intrusion Detection
    Lee, Nicholas
    Ooi, Shih Yin
    Pang, Ying Han
    COMPUTATIONAL SCIENCE AND TECHNOLOGY (ICCST 2019), 2020, 603 : 11 - 21
  • [10] A Hybrid Approach for Network Intrusion Detection
    Mehmood, Mavra
    Javed, Talha
    Nebhen, Jamel
    Abbas, Sidra
    Abid, Rabia
    Bojja, Giridhar Reddy
    Rizwan, Muhammad
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (01): : 91 - 107