首页> 外文OA文献 >Host based detection approach using time based module for fast attack detection behavior
【2h】

Host based detection approach using time based module for fast attack detection behavior

机译:基于主机的检测方法,使用基于时间的模块进行快速攻击检测

摘要

Intrusion Detection System (IDS) is an important component in a network security infrastructure. IDS need to be accurate and reliable in order to detect the intrusive behaviour of a packet that travelling through the network. With the current technological advancement attack on network infrastructure has evolve to a new level and to make IDS sensitive enough to detect the new attack, the detection framework need to be frequently updated. Both the fast attack and slow attack mechanism has become the subset of phases inside the anatomy of attack. Each of the attack mechanism has their own criteria and fast attack is the important type of attack that need to be considered as any late detection of the fast attack can cause a major bad impact to the organization. Therefore, there is a need to identify a suitable technique to detect the fast attack and based on this, this paper introduce a static threshold using statistical and observation technique for detecting the fast attack intrusion that is within one second time interval. The Threshold selected was based on the real network traffic dataset and verified using classification table on real network traffic.
机译:入侵检测系统(IDS)是网络安全基础结构中的重要组件。 IDS需要准确可靠,以便检测通过网络传播的数据包的侵入行为。随着当前技术的进步,对网络基础结构的攻击已发展到一个新的水平,并且为了使IDS足够灵敏以检测新攻击,需要经常更新检测框架。快速攻击机制和慢速攻击机制都已成为攻击结构内各个阶段的子集。每种攻击机制都有其自己的标准,快速攻击是重要的攻击类型,因此任何后期检测到的快速攻击都可能对组织造成严重不利影响,因此需要考虑快速攻击。因此,有必要找到一种合适的技术来检测快速攻击,并在此基础上,引入基于统计和观察技术的静态阈值,以检测一秒时间间隔内的快速攻击入侵。选择的阈值基于真实网络流量数据集,并使用关于真实网络流量的分类表进行验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号