首页> 外文会议>2011 7th International Conference on Information Assurance and Security >Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detection
【24h】

Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detection

机译:在网络入侵检测中使用基于统计的黑名单生成的自适应上下文感知包过滤方案

获取原文

摘要

By using string matching, signature-based network intrusion detection systems (NIDSs) can achieve a higher accuracy and lower false alarm rate than the anomaly-based systems. But the matching process is very expensive regarding to the performance of a signature-based NIDS in which the cost is at least linear to the size of the input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem greatly limits the high performance of a signature-based NIDS in a large operational network. In this paper, we present a context-aware packet filter scheme aiming to mitigate this problem. In particular, our scheme incorporates a list technique, namely the blacklist to help filter network packets based on the confidence of the IP domains. Moreover, our scheme will adapt and update the blacklist contents by using the method of statistic-based blacklist generation according to the actual network environment. In the experiment, we implemented our scheme and showed the first experimental evaluation of its effectiveness.
机译:通过使用字符串匹配,与基于异常的系统相比,基于签名的网络入侵检测系统(NIDS)可以实现更高的准确性和更低的误报率。但是,就基于签名的NIDS的性能而言,匹配过程非常昂贵,在该过程中,开销至少与输入字符串的大小成线性关系,在最坏的情况下,CPU占用率可以达到80%以上。这个问题极大地限制了大型运营网络中基于签名的NIDS的高性能。在本文中,我们提出了一种旨在缓解此问题的上下文感知包过滤器方案。特别是,我们的方案采用了列表技术,即黑名单,可根据IP域的置信度帮助过滤网络数据包。而且,我们的方案将根据实际的网络环境,采用基于统计的黑名单生成方法来适应和更新黑名单内容。在实验中,我们实施了我们的方案,并展示了其有效性的第一个实验评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号