• DocumentCode
    1591169
  • Title

    Design and implementation of a scalable intrusion detection system for the protection of network infrastructure

  • Author

    Jou, Y.F. ; Gong, F. ; Sargor, C. ; Wu, X. ; Wu, S.F. ; Chang, H.C. ; Wang, F.

  • Author_Institution
    Adv. Network Res., MCNC, Research Triangle Park, NC, USA
  • Volume
    2
  • fYear
    2000
  • fDate
    6/22/1905 12:00:00 AM
  • Firstpage
    69
  • Abstract
    This paper presents the design, implementation, and experimentation of the JiNao intrusion detection system (IDS) which focuses on the protection of the network routing infrastructure. We used the open shortest path first (OSPF) routing protocol as an implementation example to illustrate our IDS design. However, the system architecture is generic enough that the JiNao IDS can be used for protecting other protocols. The system features attack prevention and intrusion detection with tightly integrated network management components. The prevention module functions like a firewall which consists of a small set of rules. Both misuse (protocol analysis) and anomaly (statistical based) approaches are implemented as detection mechanisms in order to handle both known and unknown attacks. Four OSPF attacks (i.e., MaxSeq, MaxAge, Seq++, and LSID attacks) have been developed for evaluating JiNao´s detecting capability. Furthermore, an SNMP based network management interface has been designed and implemented such that the JiNao IDS can be easily integrated with existing network management systems
  • Keywords
    Internet; computer network management; protocols; security of data; telecommunication network routing; telecommunication security; Internet; JiNao; anomaly approach; attack prevention; firewall; integrated network management; misuse approach; network infrastructure protection; open shortest path first routing protocol; scalable intrusion detection system; system architecture; Intrusion detection; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    DARPA Information Survivability Conference and Exposition, 2000. DISCEX '00. Proceedings
  • Conference_Location
    Hilton Head, SC
  • Print_ISBN
    0-7695-0490-6
  • Type

    conf

  • DOI
    10.1109/DISCEX.2000.821510
  • Filename
    821510