首页> 外文期刊>Journal of network and computer applications >Adaptive blacklist-based packet filter with a statistic-based approach in network intrusion detection
【24h】

Adaptive blacklist-based packet filter with a statistic-based approach in network intrusion detection

机译:网络统计中基于统计的自适应黑名单包过滤

获取原文
获取原文并翻译 | 示例
           

摘要

Network intrusion detection systems (NIDS) are widely deployed in various network environments. Compared to an anomaly based NIDS, a signature-based NIDS is more popular in real-world applications, because of its relatively lower false alarm rate. However, the process of signature matching' is a key limiting factor to impede the performance of a signature-based NIDS, in which the cost is at least linear to the size of an input string and the CPU occupancy rate can reach more than 80% in the worst case. In this paper, we develop an adaptive blacklist-based packet filter using a statistic-based approach aiming to improve the performance of a signature-based NIDS. The filter employs a blacklist technique to help filter out network packets based on IP confidence and the statistic-based approach allows the blacklist generation in an adaptive way, that is, the blacklist can be updated periodically. In the evaluation, we give a detailed analysis of how to select weight values in the statistic-based approach, and investigate the performance of the packet filter with a DARPA dataset, a real dataset and in a real network environment. Our evaluation results under various scenarios show that our proposed packet filter is encouraging and effective to reduce the burden of a signature-based NIDS without affecting network security.
机译:网络入侵检测系统(NIDS)广泛部署在各种网络环境中。与基于异常的NIDS相比,基于签名的NIDS由于其相对较低的虚警率而在现实世界的应用中更为流行。但是,“签名匹配的过程”是阻碍基于签名的NIDS性能的关键限制因素,在该过程中,成本至少与输入字符串的大小成线性关系,并且CPU占用率可以达到80%以上在最坏的情况下。在本文中,我们使用基于统计的方法开发了一种自适应的基于黑名单的数据包过滤器,旨在提高基于签名的NIDS的性能。该过滤器采用黑名单技术来帮助基于IP置信度过滤出网络数据包,基于统计的方法允许以自适应方式生成黑名单,即可以定期更新黑名单。在评估中,我们详细分析了如何在基于统计的方法中选择权重值,并研究了具有DARPA数据集,真实数据集和真实网络环境中的数据包过滤器的性能。我们在各种情况下的评估结果表明,我们提出的数据包过滤器令人鼓舞并且有效地减轻了基于签名的NIDS的负担,同时又不影响网络安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号