首页> 外文会议>International Conference on Software, Knowledge Information Management and Applications >Snort Based Collaborative Intrusion Detection System Using Blockchain in SDN
【24h】

Snort Based Collaborative Intrusion Detection System Using Blockchain in SDN

机译:SNORT基于SDN中的SLOCKCHAIN的协作入侵检测系统

获取原文

摘要

Due to the rapid increment of the cyber attacks, intrusion detection system (IDS) is shifting towards collaborative approaches. There is a huge demand for securing larger networking environments for providing a safeguard against threats. In order to optimize the feasible detection performance, Collaborative Intrusion Detection Networks (CIDN) approaches have been adopted in practical scenarios, which enables a group of IDS nodes to mutually share and exchange mandatory information with each other, for example, IDS-signatures, attacks alarms. However, CIDN networks are distributed in nature, such networks still face plenty of implementation problems, especially, insider intruder can easily dominate any of security node and leave the entire security system vulnerable. To achieve the trust-based communication between each of IDS node, the recent advancement in blockchain applications is considered as a good fit to create trust-based communication in CIDN networks. This work converges CIDN network and blockchain in SDN context. Firstly, we investigated existing related work and highlighted challenges and research gap towards blockchain in CIDN networks. Secondly, we utilised three collaborated Snort IDS to receive the latest signature update from Ryu and then to securely share such signatures updates to all other Snort nodes within test-bed. Our work is motivated to detect seven types of common attacks with collaborated signature-based IDS, which feasibly processes more packets to achieve satisfactory detection results. Overall the evaluation results show that with the adoption of blockchain protocols, the proposed CIDN network achieves 96% of TP rate detection rate for TCP, UDP and ICMP packets.
机译:由于的网络攻击的迅速增加,入侵检测系统(IDS)正转向协作方法。这里是为了提供对威胁的保障确保较大的网络环境的巨大需求。为了优化的可行检测性能,协同入侵检测网络(CIDN)方法已经在实际情况下通过的,这使得一组IDS节点相互共享并彼此,例如,IDS-签名,攻击交换强制性信息报警。然而,CIDN网络分布于自然界,这样的网络面仍然充裕的执行问题,尤其是内幕入侵者可以轻易主宰任何安全节点的离开对整个安全系统的脆弱。为了实现各IDS节点之间的信任为基础的通信,近期blockchain应用的进步被认为是一个不错的选择,以创建CIDN网络基于信任的沟通。这项工作在收敛SDN方面CIDN网络和blockchain。首先,我们研究了现有朝着CIDN网络blockchain相关的工作,并强调了挑战和研究的空白。其次,我们利用立体合作的Snort IDS接收来自刘某最新的签名更新,然后安全地共享这样的签名更新到所有其他节点的Snort试验台内。我们的工作是激励检测七种与合作基于签名的入侵检测系统,它切实处理更多的数据包,以达到满意的检测结果的常见攻击。总体评价结果表明,与采用blockchain协议,建议CIDN网络实现了对TCP,UDP和ICMP数据包TP率的检出率96%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号