DocumentCode
2961859
Title
NetFlow based intrusion detection system
Author
Pao, Tang-Long ; Wang, Po-Wei
Author_Institution
Dept. Comput. Sci. & Eng., Tatung Univ., Taipei, Taiwan
Volume
2
fYear
2004
fDate
2004
Firstpage
731
Abstract
In this paper, a NetFlow based anomaly intrusion detection system is presented. In addition, guidelines to properly configure and setup network device to minimize the possibilities that network attacks come from inside are also proposed. As the Internet becomes the platform of daily activities, the threat of network attack is also become more serious. Firewall along is not able to protect the system from being attacked through normal service channel. Furthermore, most of the current intrusion detection system focuses on the border of organization network. If the attack comes from inside, this setup does not provide any protection to hosts in the local network and the network itself. Therefore, we need to use other mechanism to protect the critical system as well as the network itself. We propose an inexpensive and easy to implement way to perform the anomaly type intrusion detection based on the NetFlow data exported from the routers or other network probes. Our system can detect several types of network attack from inside or outside and perform counter maneuver accordingly.
Keywords
Internet; security of data; telecommunication security; Internet; intrusion detection system; net flow; network attack; network security; Application software; Computer science; Hardware; Home computing; IP networks; Intrusion detection; Network servers; Payloads; Protection; Wide area networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Networking, Sensing and Control, 2004 IEEE International Conference on
ISSN
1810-7869
Print_ISBN
0-7803-8193-9
Type
conf
DOI
10.1109/ICNSC.2004.1297037
Filename
1297037
Link To Document