首页> 外文会议>Network Operations and Management Symposium (NOMS), 2012 IEEE >On network intrusion detection for deployment in the wild
【24h】

On network intrusion detection for deployment in the wild

机译:关于网络入侵检测以进行野外部署

获取原文
获取原文并翻译 | 示例

摘要

As the number of network-based attacks continue to increase, network operations and management tasks become more and more complex. As we have come to depend on reliable operations of networked systems, it is important to be able to provide security measures that both efficient in terms of processing speed as well as in detecting attacks that are not in the database. To this end, anomaly-based intrusion detection systems allow detection of previously unknown and never seen attacks, and effectively complement signature-based detection schemes. In this paper, we evaluate a robust intrusion detection scheme with the goal of developing stand-alone devices that can be deployed in a plug-and-play manner to existing systems. Such devices are attractive as it allows an added security feature to quickly be deployed without adding to the management complexity of existing systems. Our system is robust in that it is resilient to contaminated traffic that may be included in real-time training. Leveraging this advantage, we show that our detection system can self-train without the need for a large, sanitized training data set typically required for many anomaly-based detection schemes. This feature naturally lends itself to faster deployment and for managing systems in changing environments. We demonstrate this concept by developing a physical prototype using an embedded platform. Our results show that amount of delay introduced by the device is small. Another attractive feature of the stand alone device is that it is impossible to temper with without physical access to the device, even if host systems are compromised.
机译:随着基于网络的攻击数量的不断增加,网络操作和管理任务变得越来越复杂。由于我们已经依赖于网络系统的可靠运行,因此重要的是能够提供安全措施,这些措施在处理速度以及检测数据库中未存在的攻击方面均有效。为此,基于异常的入侵检测系统允许检测以前未知且从未见过的攻击,并有效地补充了基于签名的检测方案。在本文中,我们评估了一种健壮的入侵检测方案,其目标是开发可以以即插即用的方式部署到现有系统的独立设备。这样的设备很吸引人,因为它允许快速部署增加的安全功能,而不会增加现有系统的管理复杂性。我们的系统很强大,可以对实时培训中可能包含的受污染的流量具有弹性。利用这一优势,我们证明了我们的检测系统可以自行训练,而无需使用许多基于异常的检测方案通常需要的大型,经过消毒的训练数据集。自然,此功能可使其更快地部署并在不断变化的环境中管理系统。我们通过使用嵌入式平台开发物理原型来演示此概念。我们的结果表明,设备引入的延迟量很小。独立设备的另一个吸引人的特点是,即使主机系统受到损害,也无法在没有物理访问设备的情况下进行调温。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号