首页> 外文会议>International Conference for Internet Technology and Secured Transactions >Real time multi stage unsupervised intelligent engine for NIDS to enhance detection rate of unknown attacks
【24h】

Real time multi stage unsupervised intelligent engine for NIDS to enhance detection rate of unknown attacks

机译:实时多阶段无监督智能发动机,用于提高未知攻击的检测率

获取原文

摘要

The most traditional technique for Network Intrusion Detection Systems (NIDSs) is misuse detection which only detects well-known attacks by matching the current behavior of network with pre-defined attacks' signatures. Providing attacks' signatures is costly, time consuming and with the explosive growing number of zero day attacks, using misuse detection mechanism is not an efficient solution. Other techniques which applied on NIDS are supervised and semi-supervised anomaly detection systems which can detect novel attacks by comparing the current behavior of the network to the training sample; however producing labeled or attack-free dataset is difficult for training the engine. Current NIDS solutions monitor bytes, packets' payload or network flows to detect intrusions. Today it is difficult to monitor the payload of packets in high speed network (1-10 Gbps) and recent network attacks are becoming more complex and analyzing only the payload of packets will not produce enough information for detection engine. In this paper we propose a new Real Time Unsupervised Network Intrusion Detection System (RTUNIDS) which monitor network flows in two windows with different sizes and detects network attacks by correlating outliers from multiple clusters. The proposed solution has the ability of detecting different types of intrusions in realtime such as DOS, DDOS, scanning, distribution of worms and any other network attacks which produce huge amount of network traffic and in the meanwhile it detects Bot-Master if the detected attack lunched by Bots.
机译:用于网络入侵检测系统(NIDS)最传统的技术是滥用检测,该检测只能通过将网络的当前行为与预定义的攻击的签名匹配来检测众所周知的攻击。提供攻击的签名是昂贵的,耗时且随着爆炸性越来越多的零日攻击数量,使用误用检测机制不是一个有效的解决方案。在NID上应用的其他技术是监督和半监督异常检测系统,可以通过将网络的当前行为与训练样本进行比较来检测新的攻击;但是,难以训练发动机难以产生标记或无攻击数据集。当前NIDS解决方案监视字节,数据包的有效载荷或网络流以检测入侵。今天,很难监视高速网络中数据包的有效载荷(1-10 Gbps),最近的网络攻击变得越来越复杂,并且分析只有数据包的有效载荷不会产生足够的检测引擎信息。在本文中,我们提出了一种新的实时无监督的网络入侵检测系统(RTUNEID),其在两个窗口中监控具有不同大小的网络流量,并通过从多个集群中关联异常值来检测网络攻击。该提出的解决方案具有检测实时诸如DOS,DDO,扫描,蠕虫的不同类型入侵的能力以及产生大量网络流量的任何其他网络攻击,同时它是检测到的攻击如果检测到的攻击用机器人午餐。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号