Enhancing network intrusion detection with integrated sampling and filtering

被引:0
|
作者
Gonzalez, Jose M. [1 ]
Paxson, Vern [1 ]
机构
[1] Int Comp Sci Inst, Berkeley, CA 94704 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The structure of many standalone network intrusion detection systems (NIDSs) centers around a chain of analysis that begins with packets captured by a packet filter, where the filter describes the protocols (TCP/UDP port numbers) and sometimes hosts or subnets to include or exclude from the analysis. In this work we argue for augmenting such analysis with an additional, separately filtered stream of packets. This "Secondary Path" supplements the "Main Path" by integrating sampling and richer forms of filtering into a NIDS's analysis. We discuss an implementation of a secondary path for the Bro intrusion detection system and enhancements we developed to the Berkeley Packet Filter to work in concert with the secondary path. Such an additional packet stream provides benefits in terms of both efficiency and ease of expression, which we illustrate by applying it to three forms of NIDS analysis: tracking very large individual connections, finding "heavy hitter" traffic streams, and implementing backdoor detectors (developed in previous work) with particular ease.
引用
收藏
页码:272 / 289
页数:18
相关论文
共 50 条
  • [21] Enhancing Intrusion Detection through Deep Learning and Generative Adversarial Network
    Rahman, Md Habibur
    Martinez, Leo, III
    Mishra, Avdesh
    Nijim, Mais
    Goyal, Ayush
    Hicks, David
    4TH INTERDISCIPLINARY CONFERENCE ON ELECTRICS AND COMPUTER, INTCEC 2024, 2024,
  • [22] Enhancing Network Intrusion Detection Model Using Machine Learning Algorithms
    Awad, Nancy Awadallah
    CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 67 (01): : 979 - 990
  • [23] Enhancing Network Intrusion Detection: A Genetic Programming Symbolic Classifier Approach
    Andelic, Nikola
    Baressi Segota, Sandi
    INFORMATION, 2024, 15 (03)
  • [24] Enhancing Robustness Against Adversarial Examples in Network Intrusion Detection Systems
    Hashemi, Mohammad J.
    Keller, Eric
    2020 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2020, : 37 - 43
  • [25] Enhancing Intrusion Detection with Explainable AI: A Transparent Approach to Network Security
    Mallampati, Seshu Bhavani
    Seetha, Hari
    CYBERNETICS AND INFORMATION TECHNOLOGIES, 2024, 24 (01) : 98 - 117
  • [26] Enhancing network intrusion detection performance using generative adversarial networks
    Zhao, Xinxing
    Fok, Kar Wai
    Thing, Vrizlynn L. L.
    COMPUTERS & SECURITY, 2024, 145
  • [27] RNNIDS: Enhancing network intrusion detection systems through deep learning
    Sohi, Soroush M.
    Seifert, Jean-Pierre
    Ganji, Fatemeh
    COMPUTERS & SECURITY, 2021, 102
  • [28] Application of Deep Neural Network with Frequency Domain Filtering in the Field of Intrusion Detection
    Wang, Zhendong
    Li, Jingfei
    Xu, Zhenyu
    Yang, Shuxin
    He, Daojing
    Chan, Sammy
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2023, 2023
  • [29] Optimal filtering techniques for intrusion detection
    Jha, S
    Kruger, L
    Kurtz, TG
    Lee, Y
    Smith, A
    Wu, ZX
    Signal Processing, Sensor Fusion, and Target Recognition XIV, 2005, 5809 : 578 - 589
  • [30] Network Intrusion Detection Using a Stacking of AI-driven Models with Sampling
    AboulEla, Samar
    Kashef, Rasha
    2024 IEEE 5TH ANNUAL WORLD AI IOT CONGRESS, AIIOT 2024, 2024, : 0157 - 0164