首页> 外国专利> SECURE ANOMALY BASED EFFICIENT REAL TIME DISTRIBUTED INTRUSION DETECTION SYSTEM (SABER-DIDS).

SECURE ANOMALY BASED EFFICIENT REAL TIME DISTRIBUTED INTRUSION DETECTION SYSTEM (SABER-DIDS).

机译:基于安全异常的高效实时分布式入侵检测系统(SABER-DIDS)。

摘要

Intrusion detection is the problem to identify unauthorized use, misuse, and abuse of computer systems by insiders and external penetrators. The new advances in the connectivity of computer systems provide greater access to external world, making it as easy as pie for intruders to avoid detection. Intrusion Detection Systems (IDSs) are based on the belief that an intruders behaviour will be noticeably different from that of a legitimate user (Anomaly-Based). A distributed IDS consists of multiple Intrusion Detection Systems (called Agents) over a large network, all of which communicate with each other, or with a central server that provides the service for advanced network monitoring, incident analysis, and instant attack data. By having these co-operative agents spread over the network interacting in a distributed fashion, incident analysts, network operations, and security department personnel are able to get a broader view of what is occurring on their network as a whole. Our system consists of two types of IDS agents: Network and Host agent. Network agent system is an anomaly based agent that employs machine learning to learn from the network and recognize unusual behaviour of network metrics (eg - size of packets, hop limit, type of packets etc). New types of the attacks are also detected with the help of entropy calculation method using the parameters i.e. packet size, source destination ip_address and input traffic volume to help differentiate between attack and normal packets. The Network Agents will also communicate with a server to access its training set periodically or on updated. Host agent system is also an intelligent agent. It will look for unusual behaviour on its own system i.e. it will look for information like (super user access, user_permission_violations external usb access, ip_tables modifiers, etc). An alarm system will also generate an alarm on illegal commands as well as external usb access. The Host agents will communicate with the Network admin as well as a central incident server for storing each ticket (which it generates when an unusual behaviour is encountered). A packet forwarding agent also forwards the unusable packets to honeypot agent which analyses those packets to gain information about them.
机译:入侵检测是识别内部人员和外部渗透者未经授权使用,滥用和滥用计算机系统的问题。计算机系统连接性方面的新进展提供了对外部世界的更多访问权限,从而使入侵者像避免访问一样容易。入侵检测系统(IDS)基于以下信念:入侵者的行为将与合法用户(基于异常)的行为明显不同。分布式IDS由大型网络上的多个入侵检测系统(称为代理)组成,它们彼此通信,或者与中央服务器通信,该中央服务器为高级网络监视,事件分析和即时攻击数据提供服务。通过使这些合作代理分布在网络上以分布式方式进行交互,事件分析人员,网络运营和安全部门人员可以更全面地了解整个网络的状况。我们的系统包含两种类型的IDS代理:网络代理和主机代理。网络代理系统是基于异常的代理,它使用机器学习从网络中学习并识别网络指标的异常行为(例如,数据包大小,跳数限制,数据包类型等)。借助信息包方法,信息包大小,源目标ip_address和输入业务量等参数的熵计算方法,还可以检测到新型攻击类型,以帮助区分攻击和正常数据包。网络代理还将与服务器通信,以定期或更新后访问其培训集。主机代理系统也是智能代理。它将查找自己系统上的异常行为,即它将查找类似信息((超级用户访问权限,user_permission_violations外部USB访问权限,ip_tables修饰符等)。警报系统还将对非法命令以及外部USB访问产生警报。主机代理将与网络管理员以及中央事件服务器进行通信,以存储每个故障单(在遇到异常行为时会生成该故障单)。数据包转发代理还将不可用的数据包转发到蜜罐代理,蜜罐代理分析这些数据包以获得有关它们的信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号