Title :
Stateful intrusion detection for high-speed network´s
Author :
Kruegel, Christopher ; Valeur, Fredrik ; Vigna, Giovanni ; Kemmerer, Richard
Author_Institution :
Reliable Software Group, California Univ., Santa Barbara, CA, USA
fDate :
6/24/1905 12:00:00 AM
Abstract :
As networks become faster there is an emerging need for security, analysis techniques that can keep up with the increased network throughput. Existing network-based intrusion detection sensors can barely, keep up with bandwidths of a few hundred Mbps. Analysis tools that can deal with higher throughput are unable to maintain state between different steps of an attack or they are limited to the analysis of packet headers. We propose a partitioning approach to network security, analysis that supports in-depth, stateful intrusion detection on high-speed links. The approach is centered around a slicing mechanism that divides the overall network traffic into subsets of manageable size. The traffic partitioning is done so that a single slice contains all the evidence necessary to detect a specific attack, making sensor-to-sensor interactions unnecessary. This paper describes the approach and presents a first experimental evaluation of its effectiveness.
Keywords :
local area networks; security of data; high-speed links; increased network throughput; network-based intrusion detection sensors; packet headers; partitioning approach; security analysis techniques; slicing mechanism; stateful intrusion detection; Bandwidth; Computer network management; Ethernet networks; High-speed networks; Intrusion detection; Performance analysis; Presses; Protection; Telecommunication traffic; Throughput;
Conference_Titel :
Security and Privacy, 2002. Proceedings. 2002 IEEE Symposium on
Print_ISBN :
0-7695-1543-6
DOI :
10.1109/SECPRI.2002.1004378