首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >On network intrusion detection for deployment in the wild
【24h】

On network intrusion detection for deployment in the wild

机译:论野生部署的网络入侵检测

获取原文

摘要

As the number of network-based attacks continue to increase, network operations and management tasks become more and more complex. As we have come to depend on reliable operations of networked systems, it is important to be able to provide security measures that both efficient in terms of processing speed as well as in detecting attacks that are not in the database. To this end, anomaly-based intrusion detection systems allow detection of previously unknown and never seen attacks, and effectively complement signature-based detection schemes. In this paper, we evaluate a robust intrusion detection scheme with the goal of developing stand-alone devices that can be deployed in a plug-and-play manner to existing systems. Such devices are attractive as it allows an added security feature to quickly be deployed without adding to the management complexity of existing systems. Our system is robust in that it is resilient to contaminated traffic that may be included in real-time training. Leveraging this advantage, we show that our detection system can self-train without the need for a large, sanitized training data set typically required for many anomaly-based detection schemes. This feature naturally lends itself to faster deployment and for managing systems in changing environments. We demonstrate this concept by developing a physical prototype using an embedded platform. Our results show that amount of delay introduced by the device is small. Another attractive feature of the stand alone device is that it is impossible to temper with without physical access to the device, even if host systems are compromised.
机译:随着基于网络的攻击次数继续增加,网络运营和管理任务变得越来越复杂。正如我们所依赖的网络系统的可靠操作,重要的是能够提供在处理速度方面有效的安全措施以及检测不在数据库中的攻击。为此,基于异常的入侵检测系统允许检测以前未知,从未见过的攻击,有效地补充基于签名的检测方案。在本文中,我们评估了一种强大的入侵检测方案,其目的是开发独立设备,可以以即插即用的方式部署到现有系统。此类设备具有吸引力,因为它允许在不添加现有系统的管理复杂性的情况下快速部署添加的安全功能。我们的系统很强大,因为它是可能包含在实时培训中的受污染流量的弹性。利用这一优势,我们表明我们的检测系统可以自动列车,而无需大量的基于异常的检测方案所需的大型消毒训练数据集。此功能自然地借助更快的部署和在更改环境中管理系统。我们通过使用嵌入式平台开发物理原型来演示该概念。我们的结果表明,设备引入的延迟量很小。单独的设备的另一个有吸引力的特征是,即使主机系统受到损害,也不可能在没有物理访问的情况下发脾气。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号