首页> 外文OA文献 >A novel intrusion detection system (IDS) architecture. Attack detection based on snort for multistage attack scenarios in a multi-cores environment.
【2h】

A novel intrusion detection system (IDS) architecture. Attack detection based on snort for multistage attack scenarios in a multi-cores environment.

机译:一种新颖的入侵检测系统(IDS)架构。针对多核环境中的多阶段攻击方案,基于snort的攻击检测。

摘要

Recent research has indicated that although security systems are developing,udillegal intrusion to computers is on the rise. The research conducted hereudillustrates that improving intrusion detection and prevention methods isudfundamental for improving the overall security of systems.udThis research includes the design of a novel Intrusion Detection System (IDS)udwhich identifies four levels of visibility of attacks. Two major areas of securityudconcern were identified: speed and volume of attacks; and complexity ofudmultistage attacks. Hence, the Multistage Intrusion Detection and PreventionudSystem (MIDaPS) that is designed here is made of two fundamental elements:uda multistage attack engine that heavily depends on attack trees and a Denial ofudService Engine. MIDaPS were tested and found to improve current intrusionuddetection and processing performances.udAfter an intensive literature review, over 25 GB of data was collected onudhoneynets. This was then used to analyse the complexity of attacks in a seriesudof experiments. Statistical and analytic methods were used to design the noveludMIDaPS.udKey findings indicate that an attack needs to be protected at 4 different levels.udHence, MIDaPS is built with 4 levels of protection. As, recent attack vectors useudlegitimate actions, MIDaPS uses a novel approach of attack trees to trace theudattacker¿s actions. MIDaPS was tested and results suggest an improvement toudcurrent system performance by 84% whilst detecting DDOS attacks within 10udminutes.
机译:最近的研究表明,尽管正在开发安全系统,但对计算机的非法入侵正在上升。 udillustrat的研究表明,改进入侵检测和预防方法对于提高系统的整体安全性是非常重要的。 ud这项研究包括设计新颖的入侵检测系统(IDS) ud,它可以识别攻击的四个可见级别。确定了两个主要的安全/令人担忧的方面:攻击的速度和数量; udmultistage攻击的复杂性。因此,此处设计的多级入侵检测和防御系统(MIDaPS)由两个基本元素组成:严重依赖攻击树的多级攻击引擎和拒绝udService引擎。对MIDaPS进行了测试,发现它们可以改善当前的入侵 uddetect和处理性能。 ud经过大量文献回顾, udhoneynet上收集了超过25 GB的数据。然后将其用于分析一系列 udof实验中的攻击复杂性。 udMIDaPS使用统计和分析方法来设计。 ud关键发现表明,攻击需要在4个不同级别进行保护。 ud因此,MIDaPS具有4个级别的保护。由于最近的攻击媒介使用了合法的动作,因此MIDaPS使用一种新颖的攻击树方法来跟踪 udattacker的动作。测试了MIDaPS,结果表明,在10分钟内检测到DDOS攻击的同时,系统的当前性能提高了84%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号