Web-based monitoring approach for network-based intrusion detection and prevention

被引:8
|
作者
Wattanapongsakorn, Naruemon [1 ]
Charnsripinyo, Chalermpol [2 ]
机构
[1] King Mongkuts Univ Technol, Dept Comp Engn, Bangkok, Thailand
[2] Natl Elect & Comp Technol Ctr, Klongluang, Pathumthani, Thailand
关键词
Web-based IDPS; Real-time detection; Intrusion detection system; Network security system; Machine learning technique;
D O I
10.1007/s11042-014-2097-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There were many reports about incidents of network attacks and security treats. Damages caused by network attacks and malwares can be extremely expensive or unaffordable. In this paper, we present a web-based management system for network-based intrusion detection and prevention. Users can get access from any mobile devices to see current network status, if there is an incident of network attack in the network environment. Our intrusion detection and prevention systems (IDPS) can be applied with different well-known detection algorithms which are C4.5 Decision Tree, Random Forest, Ripple Rule, Bayesian Network, Back-Propagation Neural Network. These algorithms can give very high detection accuracy for known attacks, where the attack type was previously trained/ learnt by the system. However, when new or unfamiliar/unknown attacks are encountered, the algorithms do not perform well. So, we develop a new detection technique based on Fuzzy Genetic Algorithm (Fuzzy GA) to handle the problem. Our IDPS can work in real-time, where detection results will be reported within 2-3 s. The IDPS will automatically protect the network by dropping the malicious network packets or block the network ports that are abused by the attackers. In addition, the proposed IDPS can detect network attacks at different locations inside the network by using several client machines to capture data packets and then send information to the server in order to classify types of network attacks. The proposed IDPS also allows system administrator to update existing detection rule sets or learn new training datasets with a friendly graphic user interface. In our experiments, we can correctly detect and prevent network attacks with high accuracy, more than 97 %.
引用
收藏
页码:6391 / 6411
页数:21
相关论文
共 50 条
  • [1] Web-based monitoring approach for network-based intrusion detection and prevention
    Naruemon Wattanapongsakorn
    Chalermpol Charnsripinyo
    [J]. Multimedia Tools and Applications, 2015, 74 : 6391 - 6411
  • [2] NetSTAT: A network-based intrusion detection approach
    Vigna, G
    Kemmerer, RA
    [J]. 14TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 1998, : 25 - 34
  • [3] Policy management for network-based intrusion detection and prevention
    Chen, YM
    Yang, YY
    [J]. NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, APPLICATION SESSIONS: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 219 - 232
  • [4] A Network-based Internet Worm Intrusion Detection and Prevention System
    Wattanapongsakorn, N.
    Wonghirunsombat, E.
    Assawaniwed, T.
    Hanchana, V.
    Srakaew, S.
    Charnsripinyo, C.
    [J]. 2013 INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2013,
  • [5] NIDS: A network based approach to intrusion detection and prevention
    Ahmed, Martuza
    Pal, Rima
    Hossain, Md. Mojammel
    Bikas, Md. Abu Naser
    Hasan, Md. Khalad
    [J]. IACSIT-SC 2009: INTERNATIONAL ASSOCIATION OF COMPUTER SCIENCE AND INFORMATION TECHNOLOGY - SPRING CONFERENCE, 2009, : 141 - 144
  • [6] A Centralized Management Framework of Network-based Intrusion Detection and Prevention System
    Wonghirunsombat, Ekgapark
    Asawaniwed, Teewalee
    Hanchana, Vassapon
    Wattanapongsakorn, Naruemon
    Srakaew, Sanan
    Charnsripinyo, Chalermpol
    [J]. 2013 10TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE), 2013, : 183 - 188
  • [7] PIDS: A packet based approach to network intrusion detection and prevention
    Ahmed, Martuza
    Pal, Rima
    Hossain, Md. Mojammel
    Bikas, Md. Abu Naser
    Ruhunnabi, Abdullahil Baki Md.
    [J]. 2009 INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND ENGINEERING, PROCEEDINGS, 2009, : 124 - 127
  • [8] Network-based Intrusion Detection: A One-class Classification Approach
    Arregoces, Paulina
    Vergara, Jaime
    Armando Gutierrez, Sergio
    Felipe Botero, Juan
    [J]. PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,
  • [9] Intrusion detection system: a deep neural network-based concatenated approach
    Sharma, Hidangmayum Satyajeet
    Singh, Khundrakpam Johnson
    [J]. JOURNAL OF SUPERCOMPUTING, 2024, 80 (10): : 13918 - 13948
  • [10] Weaknesses and Strengths Analysis over Network-based Intrusion Detection and Prevention Systems
    Guillen, Edward
    Padilla, Daniel
    Colorado, Yudy
    [J]. 2009 IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS (LATINCOM 2009), 2009, : 181 - 185