首页> 外文会议>International Conference on Information Assurance and Security >Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detection
【24h】

Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detection

机译:自适应上下文感知数据包过滤器方案使用基于统计的黑名单在网络入侵检测中生成

获取原文

摘要

By using string matching, signature-based network intrusion detection systems (NIDSs) can achieve a higher accuracy and lower false alarm rate than the anomaly-based systems. But the matching process is very expensive regarding to the performance of a signature-based NIDS in which the cost is at least linear to the size of the input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem greatly limits the high performance of a signature-based NIDS in a large operational network. In this paper, we present a context-aware packet filter scheme aiming to mitigate this problem. In particular, our scheme incorporates a list technique, namely the blacklist to help filter network packets based on the confidence of the IP domains. Moreover, our scheme will adapt and update the blacklist contents by using the method of statistic-based blacklist generation according to the actual network environment. In the experiment, we implemented our scheme and showed the first experimental evaluation of its effectiveness.
机译:通过使用字符串匹配,基于签名的网络入侵检测系统(NIDS)可以实现比基于异常的系统更高的精度和更低的误报率。但是,匹配过程对基于签名的NID的性能非常昂贵,其中成本至少线性到输入字符串的大小,并且CPU占用率可以在最坏情况下达到80%以上。这个问题极大地限制了大型操作网络中基于签名的NID的高性能。在本文中,我们介绍了一种旨在减轻此问题的上下文感知的数据包过滤器方案。特别是,我们的计划包含列表技术,即黑名单,以帮助基于IP域的置信度过滤网络数据包。此外,我们的计划将通过使用根据实际网络环境的基于统计的黑名单生成的方法来调整和更新黑名单内容。在实验中,我们实施了我们的计划,并显示了其有效性的第一个实验评价。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号