FIXIDS: A High-Speed Signature-based Flow Intrusion Detection System

被引:0
|
作者
Erlacher, Felix [1 ]
Dressler, Falko
机构
[1] Paderborn Univ, Heinz Nixdorf Inst, Paderborn, Germany
关键词
NETFLOW;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Signature-based Network Intrusion Detection Systems (NIDS) are the state-of-the-art when it comes to precise attack detection and intrusion prevention. However, they experience critical performance problems in modern high-speed networks. At the same time, flow-based network monitoring has been investigated for high data rates. In the last years, such flow-monitoring went beyond collecting statistical information about network connections and more recent techniques are able to include selected samples of the payload of these flows. Most recently, we extended this concept to HTTP flows. We now go one step further and combine IPFIX-based flow monitoring with NIDS. We developed IPFIX-based Signature-based Intrusion Detection System (FIXIDS), a system that exploits the recently introduced HTTP related flow Information Elements (IEs) to do signature-based flow intrusion detection in high-speed networks on commodity hardware. FIXIDS makes use of HTTP intrusion signatures from the widely used Snort NIDS and applies them to incoming IPFIX Flows. In the experimental evaluation, we are able to show a performance gain of a factor of three compared to Snort while maintaining the same detection ratio.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] A system architecture for high-speed deep packet inspection in signature-based network intrusion prevention
    Kim, Sunil
    Lee, Jun-yong
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2007, 53 (5-6) : 310 - 320
  • [2] Signature-Based Hybrid Intrusion detection system (HIDS) for Android devices
    Ghorbanian, Masoud
    Shanmugam, Bharanidharan
    Narayansamy, Ganthan
    Idris, Norbik Bashah
    [J]. 2013 IEEE BUSINESS ENGINEERING AND INDUSTRIAL APPLICATIONS COLLOQUIUM (BEIAC 2013), 2013, : 827 - 831
  • [3] Intrusion detection for high-speed networks based on producing system
    Chen, Ken
    Yu, Fei
    Xu, Cheng
    Liu, Yan
    [J]. FIRST INTERNATIONAL WORKSHOP ON KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2007, : 532 - +
  • [4] A Signature-Based Intrusion Detection System for Web Applications based on Genetic Algorithm
    Bronte, Robert
    Shahriar, Hossain
    Haddad, Hisham M.
    [J]. SECURITY OF INFORMATION AND NETWORKS (SIN'16), 2016, : 32 - 39
  • [5] Effective intrusion detection model through the combination of a signature-based intrusion detection system and a machine learning-based intrusion detection system
    Weon, Ill-Young
    Song, Doo Heon
    Lee, Chang-Hoon
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2006, 22 (06) : 1447 - 1464
  • [6] Intrusion detection system for high-speed network
    Yang, W
    Fang, BX
    Liu, B
    Zhang, HL
    [J]. COMPUTER COMMUNICATIONS, 2004, 27 (13) : 1288 - 1294
  • [7] Characterizing Realistic Signature-based Intrusion Detection Benchmarks
    Aldwairi, Monther
    Alshboul, Mohammad A.
    Seyam, Asmaa
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: IOT AND SMART CITY (ICIT 2018), 2018, : 97 - 103
  • [8] An Architecture for Blockchain-Enabled Collaborative Signature-based Intrusion Detection System
    Laufenberg, Daniel
    Li, Lei
    Shahriar, Hossain
    Han, Meng
    [J]. PROCEEDINGS OF THE 20TH ANNUAL CONFERENCE ON INFORMATION TECHNOLOGY EDUCATION (SIGITE '19), 2019, : 169 - 169
  • [9] Research on High-speed Network-based Intrusion Detection System
    Liu Ting
    Meng Qingwei
    [J]. 2012 7TH INTERNATIONAL CONFERENCE ON SYSTEM OF SYSTEMS ENGINEERING (SOSE), 2012, : 363 - 365
  • [10] CAMNEP: An intrusion detection system for high-speed networks
    Rehák, Martin
    Pechouček, Michal
    Bartoš, Karel
    Grill, Martin
    Čeleda, Pavel
    Krmíček, Vojtech
    [J]. Progress in Informatics, 2008, (05): : 65 - 74