Enhancing network intrusion detection with integrated sampling and filtering

被引:0
|
作者
Gonzalez, Jose M. [1 ]
Paxson, Vern [1 ]
机构
[1] Int Comp Sci Inst, Berkeley, CA 94704 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The structure of many standalone network intrusion detection systems (NIDSs) centers around a chain of analysis that begins with packets captured by a packet filter, where the filter describes the protocols (TCP/UDP port numbers) and sometimes hosts or subnets to include or exclude from the analysis. In this work we argue for augmenting such analysis with an additional, separately filtered stream of packets. This "Secondary Path" supplements the "Main Path" by integrating sampling and richer forms of filtering into a NIDS's analysis. We discuss an implementation of a secondary path for the Bro intrusion detection system and enhancements we developed to the Berkeley Packet Filter to work in concert with the secondary path. Such an additional packet stream provides benefits in terms of both efficiency and ease of expression, which we illustrate by applying it to three forms of NIDS analysis: tracking very large individual connections, finding "heavy hitter" traffic streams, and implementing backdoor detectors (developed in previous work) with particular ease.
引用
收藏
页码:272 / 289
页数:18
相关论文
共 50 条
  • [1] Enhancing network intrusion detection system with honeypot
    Yeldi, S
    Gupta, S
    Ganacharya, T
    Doshi, S
    Bahirat, D
    Ingle, R
    Roychowdhary, A
    IEEE TENCON 2003: CONFERENCE ON CONVERGENT TECHNOLOGIES FOR THE ASIA-PACIFIC REGION, VOLS 1-4, 2003, : 1521 - 1526
  • [2] PCA filtering and probabilistic SOM for network intrusion detection
    De la Hoz, Eduardo
    De La Hoz, Emiro
    Ortiz, Andres
    Ortega, Julio
    Prieto, Beatriz
    NEUROCOMPUTING, 2015, 164 : 71 - 81
  • [3] An Integrated Approach to Network Intrusion Detection and Prevention
    Prakash, B. Bhanu
    Yeswanth, Kaki
    Srinivas, M. Sai
    Balaji, S.
    Sekhar, Y. Chandra
    Nair, Aswathy K.
    INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES, ICICCT 2019, 2020, 89 : 43 - 51
  • [4] Enhancing intrusion detection with feature selection and neural network
    Wu, Chunhui
    Li, Wenjuan
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2021, 36 (07) : 3087 - 3105
  • [5] Enhancing network based intrusion detection for imbalanced data
    Engen, Vegard
    Vincent, Jonathan
    Phalp, Keith
    INTERNATIONAL JOURNAL OF KNOWLEDGE-BASED AND INTELLIGENT ENGINEERING SYSTEMS, 2008, 12 (5-6) : 357 - 367
  • [6] Network Intrusion Detection Combined Hybrid Sampling With Deep Hierarchical Network
    Jiang, Kaiyuan
    Wang, Wenya
    Wang, Aili
    Wu, Haibin
    IEEE ACCESS, 2020, 8 : 32464 - 32476
  • [7] Intrusion Detection in the Era of loT: Building Trust via Traffic Filtering and Sampling
    Meng, Weizhi
    COMPUTER, 2018, 51 (07) : 36 - 43
  • [8] The network management design integrated with the intrusion detection system
    Zhang, XY
    Li, CZ
    Hu, QG
    PROCEEDINGS OF THE 2004 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2004, : 257 - 262
  • [9] Feedback based Sampling for Intrusion Detection in Software Defined Network
    Shi, Jiangyong
    Zeng, Yingzhi
    Wang, Wenhao
    Yang, Yuexiang
    ICCSP 2018: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, 2018, : 95 - 99
  • [10] Enhancing IoT Network Security: ML and Blockchain for Intrusion Detection
    Sunanda, N.
    Shailaja, K.
    Kandukuri, Prabhakar
    Krishnamoorthy
    Rao, Vuda Sreenivasa
    Godla, Sanjiv Rao
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (04) : 947 - 958