首页> 外文期刊>International journal of computer science and network security >Defend Against Ransomware Detection Using Intrusion Detection System (IDS)
【24h】

Defend Against Ransomware Detection Using Intrusion Detection System (IDS)

机译:使用入侵检测系统(IDS)防御赎金软件检测

获取原文
           

摘要

Ransomware is currently one of the most impactful forms of cyber-attacks available. One of the greatest challenges posed by ransom ware is the extremely large number and diversity of ransom ware families, and the fact that new ransom ware variants are being released by cybercriminals on a regular basis. In this paper, studied different ransom ware families, and identified several distinctive characteristics and attributes that could be used in early detection of ransom ware based on network traffic analysis. Intrusion Detection System (IDS) is a type of security software designed to automatically alert administrators when someone or something is trying to compromise information system through malicious activities or through security policy violations. Institution network is a complex infrastructure consisting of multiple virtual local area networks “VLANs” separating the different departments, laboratories and facilities according to their functions. Institution Network border consists of a firewall which oversees the ingoing and outgoing traffic and also has a manual monitoring system which logs intrusion attempts. To perform any action against an intrusion the administrator has to perform any action manually. The aim of this paper is to provide an intrusion detection system to be deployed on the Institution Network infrastructure. The IDS will be in the form of an Agent which is located on the network’s border acting as the second line of defense behind the firewall, the agent will analyze network traffic by comparing the behavior with a database containing certain measures hence classifying the user.
机译:RansomWare目前是最有影响的网络攻击形式之一。赎金洁具所带来的最大挑战之一是赎金洁具家庭的极大数量和多样性,并定期被网络犯罪分子释放新的赎金洁具变体。在本文中,研究了不同的赎金洁具系列,并确定了几种可用于基于网络流量分析的赎金件的早期检测的若干独特特征和属性。入侵检测系统(IDS)是一种用于当某人或某事物正在尝试通过恶意活动或通过安全策略违规时妥协信息系统时自动警告管理员的安全软件。机构网络是一个复杂的基础设施,包括多个虚拟本地网络“VLAN”,根据其功能分离不同的部门,实验室和设施。机构网络边界包括一个防火墙,负责监督Imoing和传出流量,并且还具有记录入侵尝试的手动监控系统。要对侵扰执行任何操作,管理员必须手动执行任何操作。本文的目的是提供一种在机构网络基础设施上部署的入侵检测系统。 IDS将以代理的形式,位于网络边框上的代理,该代理是防火墙后面的第二行防线,代理将通过比较包含某些措施的数据库来分析网络流量来分类用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号