网络安全挑战:一种高效的入侵检测系统设计

M. Kabir, Sven Hartmann
{"title":"网络安全挑战:一种高效的入侵检测系统设计","authors":"M. Kabir, Sven Hartmann","doi":"10.1109/YEF-ECE.2018.8368933","DOIUrl":null,"url":null,"abstract":"The importance of accurate intrusion detection is growing tremendously as the malicious network traffic activities have also grown significantly. Intrusion Detection Systems (IDSs) provide automatic detection for security violation like denial of service (DoS), virus, port scans, buffer overflows, CGI attacks, clogging or flooding etc. For network and host based systems, the most widely used and effective approach is data analysis with signature-based detection methods. Thus, the success of the detection system depends on the real appearance of the security violation, detection of the violation and response time. We are working on highly efficient real time network intrusion detection systems (NIDS) which will solve the detection efficiency problem such as real time detection rate, false positive etc in distributed environments. In this work, we propose a concept IDS to investigate the experimental performance of Snort based NIDS. We have used an open source network intrusion detection and prevention system Snort to implement our two different indexing methods. We used Snort version 2.9.7.5 which has almost 26k Snort rules and very efficient for online network auditing. We implemented prefix and random indexing method to all Snort rules to create primary patterns that reduce packet inspection time. Since all highly sensitive positive alerts need instant action from network administrator, our concept IDS also reduces the false positive (wrong alert) rate even at high network traffic. By combining the concept IDS and a data mining technique indexing will improve the accuracy of the intrusion detection in real time. We also present our experimental data and results of our IDS prototype.","PeriodicalId":315757,"journal":{"name":"2018 International Young Engineers Forum (YEF-ECE)","volume":"93 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"21","resultStr":"{\"title\":\"Cyber security challenges: An efficient intrusion detection system design\",\"authors\":\"M. Kabir, Sven Hartmann\",\"doi\":\"10.1109/YEF-ECE.2018.8368933\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The importance of accurate intrusion detection is growing tremendously as the malicious network traffic activities have also grown significantly. Intrusion Detection Systems (IDSs) provide automatic detection for security violation like denial of service (DoS), virus, port scans, buffer overflows, CGI attacks, clogging or flooding etc. For network and host based systems, the most widely used and effective approach is data analysis with signature-based detection methods. Thus, the success of the detection system depends on the real appearance of the security violation, detection of the violation and response time. We are working on highly efficient real time network intrusion detection systems (NIDS) which will solve the detection efficiency problem such as real time detection rate, false positive etc in distributed environments. In this work, we propose a concept IDS to investigate the experimental performance of Snort based NIDS. We have used an open source network intrusion detection and prevention system Snort to implement our two different indexing methods. We used Snort version 2.9.7.5 which has almost 26k Snort rules and very efficient for online network auditing. We implemented prefix and random indexing method to all Snort rules to create primary patterns that reduce packet inspection time. Since all highly sensitive positive alerts need instant action from network administrator, our concept IDS also reduces the false positive (wrong alert) rate even at high network traffic. By combining the concept IDS and a data mining technique indexing will improve the accuracy of the intrusion detection in real time. We also present our experimental data and results of our IDS prototype.\",\"PeriodicalId\":315757,\"journal\":{\"name\":\"2018 International Young Engineers Forum (YEF-ECE)\",\"volume\":\"93 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-05-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"21\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 International Young Engineers Forum (YEF-ECE)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/YEF-ECE.2018.8368933\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Young Engineers Forum (YEF-ECE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/YEF-ECE.2018.8368933","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 21

摘要

随着恶意网络流量活动的急剧增加,准确的入侵检测变得越来越重要。入侵检测系统(ids)提供对安全违规的自动检测,如拒绝服务(DoS)、病毒、端口扫描、缓冲区溢出、CGI攻击、阻塞或洪水等。对于基于网络和主机的系统,最广泛和有效的方法是使用基于签名的检测方法进行数据分析。因此,检测系统的成功与否取决于安全违规的真实出现、违规的检测和响应时间。为了解决分布式环境下的实时检测率、误报等检测效率问题,我们正在研究高效的实时网络入侵检测系统。在这项工作中,我们提出了一个概念IDS来研究基于Snort的NIDS的实验性能。我们使用了一个开源的网络入侵检测和防御系统Snort来实现我们的两种不同的索引方法。我们使用的是Snort版本2.9.7.5,它有近26k条Snort规则,对在线网络审计非常有效。我们对所有Snort规则实现了前缀和随机索引方法,以创建减少包检查时间的主要模式。由于所有高度敏感的正警报都需要网络管理员立即采取行动,因此我们的概念IDS即使在高网络流量下也可以降低误报(错误警报)率。将入侵检测的概念与数据挖掘技术相结合,可以提高入侵检测的实时准确性。我们还介绍了我们的IDS原型的实验数据和结果。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Cyber security challenges: An efficient intrusion detection system design
The importance of accurate intrusion detection is growing tremendously as the malicious network traffic activities have also grown significantly. Intrusion Detection Systems (IDSs) provide automatic detection for security violation like denial of service (DoS), virus, port scans, buffer overflows, CGI attacks, clogging or flooding etc. For network and host based systems, the most widely used and effective approach is data analysis with signature-based detection methods. Thus, the success of the detection system depends on the real appearance of the security violation, detection of the violation and response time. We are working on highly efficient real time network intrusion detection systems (NIDS) which will solve the detection efficiency problem such as real time detection rate, false positive etc in distributed environments. In this work, we propose a concept IDS to investigate the experimental performance of Snort based NIDS. We have used an open source network intrusion detection and prevention system Snort to implement our two different indexing methods. We used Snort version 2.9.7.5 which has almost 26k Snort rules and very efficient for online network auditing. We implemented prefix and random indexing method to all Snort rules to create primary patterns that reduce packet inspection time. Since all highly sensitive positive alerts need instant action from network administrator, our concept IDS also reduces the false positive (wrong alert) rate even at high network traffic. By combining the concept IDS and a data mining technique indexing will improve the accuracy of the intrusion detection in real time. We also present our experimental data and results of our IDS prototype.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信