Enhancing network intrusion detection with integrated sampling and filtering

被引:0
|
作者
Gonzalez, Jose M. [1 ]
Paxson, Vern [1 ]
机构
[1] Int Comp Sci Inst, Berkeley, CA 94704 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The structure of many standalone network intrusion detection systems (NIDSs) centers around a chain of analysis that begins with packets captured by a packet filter, where the filter describes the protocols (TCP/UDP port numbers) and sometimes hosts or subnets to include or exclude from the analysis. In this work we argue for augmenting such analysis with an additional, separately filtered stream of packets. This "Secondary Path" supplements the "Main Path" by integrating sampling and richer forms of filtering into a NIDS's analysis. We discuss an implementation of a secondary path for the Bro intrusion detection system and enhancements we developed to the Berkeley Packet Filter to work in concert with the secondary path. Such an additional packet stream provides benefits in terms of both efficiency and ease of expression, which we illustrate by applying it to three forms of NIDS analysis: tracking very large individual connections, finding "heavy hitter" traffic streams, and implementing backdoor detectors (developed in previous work) with particular ease.
引用
收藏
页码:272 / 289
页数:18
相关论文
共 50 条
  • [31] An integrated model of intrusion detection based on neural network and expert system
    Pan, ZS
    Lian, H
    Hu, GY
    Ni, GQ
    ICTAI 2005: 17TH IEEE INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2005, : 671 - 672
  • [32] Research on Network Intrusion Detection Model Based on Hybrid Sampling and Deep Learning
    Guo, Derui
    Xie, Yufei
    SENSORS, 2025, 25 (05)
  • [33] Network Intrusion Detection and Mitigation Using Hybrid Optimization Integrated Deep Q Network
    Emil Selvan, G. S. R.
    Daniya, T.
    Ananth, J. P.
    Suresh Kumar, K.
    CYBERNETICS AND SYSTEMS, 2024, 55 (01) : 107 - 123
  • [34] NETWORK INTRUSION DETECTION
    MUKHERJEE, B
    HEBERLEIN, LT
    LEVITT, KN
    IEEE NETWORK, 1994, 8 (03): : 26 - 41
  • [35] Multiple Kernel Transfer Learning for Enhancing Network Intrusion Detection in Encrypted and Heterogeneous Network Environments
    Amamra, Abdelfattah
    Terrelonge, Vincent
    ELECTRONICS, 2025, 14 (01):
  • [36] Enhancing Network Intrusion Detection Using an Ensemble Voting Classifier for Internet of Things
    Farooqi, Ashfaq Hussain
    Akhtar, Shahzaib
    Rahman, Hameedur
    Sadiq, Touseef
    Abbass, Waseem
    SENSORS, 2024, 24 (01)
  • [37] Dynamic multi-scale topological representation for enhancing network intrusion detection
    Zhong, Meihui
    Lin, Mingwei
    He, Zhu
    COMPUTERS & SECURITY, 2023, 135
  • [38] Enhancing IoT Network Security Using Feature Selection for Intrusion Detection Systems
    Almohaimeed, Muhannad
    Albalwy, Faisal
    APPLIED SCIENCES-BASEL, 2024, 14 (24):
  • [39] Enhancing trustworthiness in ML-based network intrusion detection with uncertainty quantification
    Talpini, Jacopo
    Sartori, Fabio
    Savi, Marco
    Journal of Reliable Intelligent Environments, 2024, 10 (04) : 501 - 520
  • [40] A Sampling Method for Intrusion Detection System
    Ning, Zhuo
    Gong, Jian
    CHALLENGES FOR NEXT GENERATION NETWORK OPERATIONS AND SERVICE MANAGEMENT, PROCEEDINGS, 2008, 5297 : 419 - 428