首页> 外文会议>International Symposium on Recent Advances in Intrusion Detection(RAID 2006); 20060920-22; Hamburg(DE) >Enhancing Network Intrusion Detection with Integrated Sampling and Filtering
【24h】

Enhancing Network Intrusion Detection with Integrated Sampling and Filtering

机译:通过集成的采样和过滤功能增强网络入侵检测

获取原文
获取原文并翻译 | 示例

摘要

The structure of many standalone network intrusion detection systems (NIDSs) centers around a chain of analysis that begins with packets captured by a packet filter, where the filter describes the protocols (TCP/UDP port numbers) and sometimes hosts or subnets to include or exclude from the analysis. In this work we argue for augmenting such analysis with an additional, separately filtered stream of packets. This "Secondary Path" supplements the "Main Path" by integrating sampling and richer forms of filtering into a NIDS's analysis. We discuss an implementation of a secondary path for the Bro intrusion detection system and enhancements we developed to the Berkeley Packet Filter to work in concert with the secondary path. Such an additional packet stream provides benefits in terms of both efficiency and ease of expression, which we illustrate by applying it to three forms of NIDS analysis: tracking very large individual connections, finding "heavy hitter" traffic streams, and implementing backdoor detectors (developed in previous work) with particular ease.
机译:许多独立的网络入侵检测系统(NIDS)的结构围绕着分析链,该分析链从数据包过滤器捕获的数据包开始,该过滤器描述了协议(TCP / UDP端口号),有时还包括或排除了主机或子网从分析。在这项工作中,我们主张通过附加的,单独过滤的数据包流来增强这种分析。该“次要路径”通过将采样和更丰富的过滤形式集成到NIDS的分析中来补充“主要路径”。我们讨论了Bro入侵检测系统的辅助路径的实现,以及我们为伯克利分组过滤器开发的与辅助路径协同工作的增强功能。这样一个额外的数据包流在效率和易于表达方面均带来了好处,我们将其应用于三种形式的NIDS分析中进行了说明:跟踪非常大的单个连接,查找“大量用户”流量以及实现后门检测器(已开发)在先前的工作中)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号