A security policy and Network Cartography based Intrusion Detection and Prevention Systems

被引:0
|
作者
Meharouech, Sourour [1 ]
Bouhoula, Adel [1 ]
Abbes, Tarek [1 ]
机构
[1] Higher Sch Telecommun SupCom, Dept Comp Sci & Networks, Digital Secur unit, Cit El Ghazala 2083, Tunisia
来源
关键词
Network security; Intrusion Detection System; Intrusion Prevention System; Security Policy; Network cartography;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During this time when Internet provides essential communication between an infinite numbers of people and is being increasingly used as a tool for commerce, security becomes a tremendously important issue to deal with. Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are now considered a mainstream security technology. IDS and IPS are designed to identify security breaches. However, one of the most problems with current IDS and IPS is the lack of the "environmental awareness" (i.e. security policy, network topology and software). This ignorance triggers many false positives and false negatives. a false negative is corresponding to a non-detected attack and it occurs because an attacker is misclassified as a normal user. A false positive is corresponding to a false alert and it occurs because the IDS/IPS misinterprets normal packets or activities as attacks. In this paper, we propose a novel intrusion detection and prevention architecture where we integrate the characteristics and the properties of the protected system in the traffic analysis process. Our solution has been verified in IDS and IPS system and achieved a significant reduction in the number of false positives and false negatives.
引用
收藏
页码:279 / 291
页数:13
相关论文
共 50 条
  • [1] Security Implications of Network Address Translation on Intrusion Detection and Prevention Systems
    Sourour, Meharouech
    Adel, Bouhoula
    Tarek, Abbes
    [J]. 2009 INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE SECURITY, 2009, : 1 - 5
  • [2] Policy management for network-based intrusion detection and prevention
    Chen, YM
    Yang, YY
    [J]. NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, APPLICATION SESSIONS: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 219 - 232
  • [3] Strengthening Network Security: Evaluation of Intrusion Detection and Prevention Systems Tools in Networking Systems
    Prabowo, Wahyu Adi
    Fauziah, Khusnul
    Nahrowi, Aufa Salsabila
    Faiz, Muhammad Nur
    Muhammad, Arif Wirawan
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (09) : 1 - 10
  • [4] Policy-Based Security Configuration Management Application to Intrusion Detection and Prevention
    Alsubhi, Khalid
    Aib, Issam
    Francois, Jerome
    Boutaba, Raouf
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 1051 - +
  • [5] Security configuration management in Intrusion Detection and Prevention Systems
    Alsubhi, K.
    Alhazmi, Y.
    Bouabdallah, N.
    Boutaba, R.
    [J]. International Journal of Security and Networks, 2012, 7 (01) : 30 - 39
  • [6] Intrusion Detection and Prevention Systems (IDPS) and Security Issues
    Sharifi, A. Ahmad
    Noorollahi, B. Akram
    Farokhmanesh, Farnoosh
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2014, 14 (11): : 80 - 84
  • [7] Intrusion Detection and Prevention using Honeypot Network for Cloud Security
    Negi, Poorvika Singh
    Garg, Aditya
    Lal, Roshan
    [J]. PROCEEDINGS OF THE CONFLUENCE 2020: 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING, 2020, : 129 - 132
  • [8] Study of Intrusion Detection Systems (IDSs) in Network Security
    Wu Junqi
    Hu Zhengbing
    [J]. 2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 4532 - +
  • [9] A study on network security monitoring for the hybrid classification-based intrusion prevention systems
    Rodas, Oscar
    To, Marco Antonio
    [J]. INTERNATIONAL JOURNAL OF SPACE-BASED AND SITUATED COMPUTING, 2015, 5 (02) : 115 - 125
  • [10] Intrusion detection and prevention systems in industrial IoT network
    Sharma, Sangeeta
    Kumar, Ashish
    Rathore, Navdeep Singh
    Sharma, Shivanshu
    [J]. SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2024, 49 (03):