Title :
A comprehensive design for decision engine in network intrusion detection and prevention system
Author :
Karbaschian, A.R. ; Mirpuryan, M.S. ; Tavizi, T.
Author_Institution :
Dept. of Comput. Eng., Islamic Azad Univ. Tehran, Tehran, Iran
Abstract :
In order to utilize benefits and remove disadvantages of both misuse and anomaly based intrusion detection systems, hybrid architectures has been offered. In the case of parallel hybrid architecture, it´s necessary that a decision engine combines both outputs of misuse and anomaly based detection systems and infers the final result. Since there is no complete solution in literature, in this paper we present our novel and comprehensive design for decision engine in hybrid network intrusion detection and prevention Systems. The overall tasks of our decision engine is firstly combining and correlating input alerts and creating meta alert, secondly inferring proper reaction corresponding to created meta alert. In our architecture, there is the possibility to apply various types of reactions. Since real time reaction is very important for overall performance, and decision making for this type of reaction highly depends on attack type, in this paper we experiment the attack classification part of our design over labeled KDD´99 dataset by attack types. Results show that our used approach has 98.0484 % accuracy of attack classification in reasonable speed.
Keywords :
decision making; security of data; anomaly based intrusion detection; attack classification; decision engine; decision making; hybrid network intrusion detection; hybrid network intrusion prevention; input alerts; labeled KDD´99 dataset; meta alert; misuse based intrusion detection; parallel hybrid architecture; real time reaction; Accuracy; Correlation; Decision making; Engines; Intrusion detection; Ontologies; NIDPS; alert; correlation; decision; design; engine; infer; prevention; reaction; response;
Conference_Titel :
Telecommunications (IST), 2012 Sixth International Symposium on
Conference_Location :
Tehran
Print_ISBN :
978-1-4673-2072-6
DOI :
10.1109/ISTEL.2012.6483125