Stateful intrusion detection for high-speed networks

被引:100
|
作者
Kruegel, C [1 ]
Valeur, F [1 ]
Vigna, G [1 ]
Kemmerer, R [1 ]
机构
[1] Univ Calif Santa Barbara, Reliable Software Grp, Santa Barbara, CA 93106 USA
来源
2002 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS | 2002年
关键词
intrusion detection; high-speed networks; security analysis;
D O I
10.1109/SECPRI.2002.1004378
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As networks become faster there is an emerging need for security analysis techniques that can keep up with the increased network throughput. Existing network-based intrusion detection sensors can barely keep zip with bandwidths of a few hundred Mbps. Analysis tools that can deal with higher throughput are unable to maintain state between different steps of an attack or they are limited to the analysis of packet headers. We propose a partitioning approach to network security analysis that supports in-depth, stateful intrusion detection on high-speed links. The approach is centered around a slicing mechanism that divides the overall network, traffic into subsets of manageable size. The traffic partitioning is done so that a single slice contains all the evidence necessary to detect a specific attack, making sensor-to-sensor interactions unnecessary. This paper describes the approach and presents a first experimental evaluation of its effectiveness.
引用
收藏
页码:285 / 293
页数:9
相关论文
共 50 条
  • [1] A Parallel Architecture for Stateful, High-Speed Intrusion Detection
    Foschini, Luca
    Thapliyal, Ashish V.
    Cavallaro, Lorenzo
    Kruegel, Christopher
    Vigna, Giovanni
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2008, 5352 : 203 - 220
  • [2] A stateful real time intrusion detection system for high-speed network
    Sourour, Meharouech
    Adel, Bouhoula
    Tarek, Abbes
    21st International Conference on Advanced Networking and Applications, Proceedings, 2007, : 404 - 411
  • [3] Efficient Intrusion Detection for High-speed Networks
    Ma, Gaolong
    Tang, Wen
    INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY, PTS 1-4, 2013, 263-266 : 2915 - 2919
  • [4] Architecture of intrusion detection for high-speed networks
    Chen, Xun-Xun
    Fang, Bin-Xing
    Li, Lei
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2004, 41 (09): : 1481 - 1487
  • [5] Intrusion detection and simulation for high-speed networks
    Yu, F
    Dai, XP
    Shen, Y
    Huang, H
    Zhu, ML
    2005 INTERNATIONAL CONFERENCE ON SERVICES SYSTEMS AND SERVICES MANAGEMENT, VOLS 1 AND 2, PROCEEDINGS, 2005, : 835 - 840
  • [6] CAMNEP: An intrusion detection system for high-speed networks
    Rehák, Martin
    Pěchouček, Michal
    Bartoš, Karel
    Grill, Martin
    Čeleda, Pavel
    Krmíček, Vojtěch
    Progress in Informatics, 2008, (05): : 65 - 74
  • [7] A parallel intrusion detection system for high-speed networks
    Lai, HG
    Cai, SW
    Huang, H
    Xie, JY
    Li, H
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PROCEEDINGS, 2004, 3089 : 439 - 451
  • [8] Evaluating Network Intrusion Detection Systems for High-Speed Networks
    Hu, Qinwen
    Asghar, Muhammad Rizwan
    Brownlee, Nevil
    2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2017, : 402 - 407
  • [9] Intrusion detection for high-speed networks based on producing system
    Chen, Ken
    Yu, Fei
    Xu, Cheng
    Liu, Yan
    FIRST INTERNATIONAL WORKSHOP ON KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2007, : 532 - +
  • [10] Real-time intrusion detection for high-speed networks
    Jiang, WB
    Song, H
    Dai, YQ
    COMPUTERS & SECURITY, 2005, 24 (04) : 287 - 294