DocumentCode
2535955
Title
Towards Intelligent Cross Protocol Intrusion Detection in the Next Generation Networks based on Protocol Anomaly Detection
Author
Barry, Bazara I A ; Chan, H. Anthony
Author_Institution
Dept. of Electr. Eng., Cape Town Univ., Rondebosch
Volume
3
fYear
2007
fDate
12-14 Feb. 2007
Firstpage
1505
Lastpage
1510
Abstract
The open nature of the next generation networks (NGNs) and the involvement of multiple protocols in a single session, along with the attacks that spread multiple protocols, pose new challenges to intrusion detection systems (IDSs). Detecting attacks based on information taken from a single protocol or a group of protocols at a certain layer results in a high rate of false positives or false negatives. In this paper, we introduce a new cross protocol design for IDSs in the NGNs based on protocol anomaly detection. Our design aims at correlating various detection results from the protocols involved in a session, both, horizontally and vertically. By horizontal correlation we aim at monitoring sessions taking place within a single layer of the protocol stack, whereas, vertical correlation addresses sessions taking place across multiple protocol layers. In addition, our design is supported by intelligent mechanism based on fuzzy logic to help the system reduce the rate of false alarms which is relatively high in many anomaly based intrusion detection systems. This paper presents the basic features of our design, emphasizing the components and the interactions between them.
Keywords
computer networks; fuzzy logic; protocols; security of data; IDS; NGN; fuzzy logic; intelligent cross protocol intrusion detection; intrusion detection systems; next generation networks; protocol anomaly detection; vertical correlation; Cities and towns; Fuzzy logic; IP networks; Intelligent networks; Internet telephony; Intrusion detection; Monitoring; Next generation networking; Telecommunication traffic; Transport protocols; Cross protocol; fuzzy logic; intrusion detection; protocol anomaly detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Communication Technology, The 9th International Conference on
Conference_Location
Gangwon-Do
ISSN
1738-9445
Print_ISBN
978-89-5519-131-8
Type
conf
DOI
10.1109/ICACT.2007.358653
Filename
4195455
Link To Document