首页> 外文会议>ICERD2010 >An Adaptive Approach to Improve the Accuracy of Packet Pre-Filtering
【24h】

An Adaptive Approach to Improve the Accuracy of Packet Pre-Filtering

机译:提高数据包预滤波精度的自适应方法

获取原文

摘要

The current day networks are under deliberate, continuous and premeditated attacks such as Hacker attacks, DoS attacks, IP Address Spoofing, Phishing, Sniffer attacks etc. The Network Intrusion Detection Systems (NIDS) proved to be reliable in parrying most of the issues and challenges faced by the corporate network security systems. But, the NID systems fall short in providing a completely fool -proof network security environment. False negatives and false positives proved to be considerable bottle necks in securing the networks from the attacks. This paper deals with the introduction of a software approach for the packet pre-filtering to ease security threats and the introduction of Network Behavior Analysis to enhance the security of the network. The Network Behavior Analysis helps the system to ease the burdens to the network and security of the network by the false positives. The NIDS compares all the incoming packets with the predefined rules or signatures to find suspicious patterns. The pre-filtering approach used in this paper is a result of the observation that very rarely an incoming packet matches the signatures or the IDS rules. During the pre-filtering step, a small portion of the packet is compared against the predefined signatures for any suspicious patterns and the initial pre-filtering match is considered for a full match. For time efficiency, this strategy is compared to more optimistic schemes that allow reassignment of flows between threads, and evaluated using several network packet traces.
机译:目前的日期网络是在刻意的,连续和预谋的攻击之类的,如黑客攻击,DOS攻击,IP地址欺骗,网络钓鱼,嗅探攻击等。网络入侵检测系统(NID)证明在绘制大部分问题和挑战方面是可靠的面对公司网络安全系统。但是,NID系统在提供完全恶心的网络安全环境方面尚不缩短。错误的否定和误报证明是可观的瓶颈,用于保护网络免受攻击。本文涉及引入数据包预过滤的软件方法,以简化安全威胁和引入网络行为分析,以增强网络的安全性。网络行为分析有助于系统通过误报使其能够对网络的网络和网络的安全性。 NIDS将所有传入数据包与预定义规则或签名进行比较,以查找可疑模式。本文中使用的预过滤方法是观察的结果,即重点传入数据包匹配签名或IDS规则。在预过滤步骤期间,将小部分分组与任何可疑模式的预定义签名进行比较,并且考虑完全匹配的初始预滤波匹配。对于时间效率,将该策略与更乐观的方案进行比较,允许使用多个网络分组跟踪进行重新分配流程之间的流程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号