Scan Detection in High-Speed Networks Based on Optimal Dynamic Bit Sharing

被引:0
|
作者
Li, Tao [1 ]
Chen, Shigang [1 ]
Luo, Wen [1 ]
Zhang, Ming [1 ]
机构
[1] Univ Florida, Dept Comp & Informat Sci & Engn, Gainesville, FL 32611 USA
关键词
ALGORITHMS;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Scan detection is one of the most important functions in intrusion detection systems. In order to keep up with the ever-higher line speed, recent research trend is to implement scan detection in fast but small SRAM. This leads to a difficult technical challenge because the amount of traffic to be monitored is huge but the on-die memory space for performing such a monitoring task is very limited. We propose an efficient scan detection scheme based on dynamic bit sharing, which incorporates probabilistic sampling and bit sharing for compact information storage. We design a maximum likelihood estimation method to extract per-source information from the shared bits in order to determine the scanners. Our new scheme ensures that the false positive/false negative ratios are bounded with high probability. Moreover, given an arbitrary set of bounds, we develop a systematic approach to determine the optimal system parameters that minimize the amount of memory needed to meet the bounds. Experiments based on a real Internet traffic trace demonstrate that the proposed scan detection scheme reduces memory consumption by three to twenty times when comparing with the best existing work.
引用
收藏
页码:3200 / 3208
页数:9
相关论文
共 50 条
  • [1] A Multi-resolution Port Scan Detection Technique for High-speed Networks
    Moon, Hwashin
    Yi, Sungwon
    Choi, Gyu Sang
    Jeon, Yongsung
    Kim, Joengnyeo
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2015, 31 (05) : 1613 - 1632
  • [2] Optimal solutions for a dynamic bandwidth allocation scheme in high-speed networks
    Yang, T
    Yei, J
    [J]. TELECOMMUNICATION SYSTEMS, 1996, 5 (04) : 389 - 412
  • [3] Spreader Classification Based on Optimal Dynamic Bit Sharing
    Li, Tao
    Chen, Shigang
    Luo, Wen
    Zhang, Ming
    Qiao, Yan
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2013, 21 (03) : 817 - 830
  • [4] Dynamic Detection and Expulsion Buffer Management Scheme for High-Speed Networks
    Yang, Jui-Pin
    [J]. IEICE TRANSACTIONS ON COMMUNICATIONS, 2011, E94B (08) : 2243 - 2246
  • [5] Optimal scan trajectories for high-speed scanning probe microscopy
    Tuma, Tomas
    Lygeros, John
    Sebastian, Abu
    Pantazi, Angeliki
    [J]. 2012 AMERICAN CONTROL CONFERENCE (ACC), 2012, : 3791 - 3796
  • [6] Intrusion detection for high-speed networks based on producing system
    Chen, Ken
    Yu, Fei
    Xu, Cheng
    Liu, Yan
    [J]. FIRST INTERNATIONAL WORKSHOP ON KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2007, : 532 - +
  • [7] Efficient Intrusion Detection for High-speed Networks
    Ma, Gaolong
    Tang, Wen
    [J]. INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY, PTS 1-4, 2013, 263-266 : 2915 - 2919
  • [8] Collaborative attack detection in high-speed networks
    Rehak, Martin
    Pechoucek, Michal
    Celeda, Pavel
    Krmicek, Vojtech
    Minarik, Pavel
    Medvigy, David
    [J]. MULTI-AGENT SYSTEMS AND APPLICATIONS V, PROCEEDINGS, 2007, 4696 : 73 - +
  • [9] Optimal bit-level arithmetic optimisation for high-speed circuits
    Um, J
    Kim, T
    [J]. ELECTRONICS LETTERS, 2000, 36 (05) : 405 - 407
  • [10] Intrusion detection and simulation for high-speed networks
    Yu, F
    Dai, XP
    Shen, Y
    Huang, H
    Zhu, ML
    [J]. 2005 INTERNATIONAL CONFERENCE ON SERVICES SYSTEMS AND SERVICES MANAGEMENT, VOLS 1 AND 2, PROCEEDINGS, 2005, : 835 - 840