• DocumentCode
    2901279
  • Title

    Kernel-level intrusion detection system for minimum packet loss

  • Author

    Bo-Heung Chung ; Jeong-Nyeo Kim ; Sung-Won Sohn ; Chee-hang Park

  • Author_Institution
    Electronics and Telecommunications Research Institute(ETRI)
  • Volume
    1
  • fYear
    2004
  • fDate
    9-11 Feb. 2004
  • Firstpage
    207
  • Lastpage
    212
  • Abstract
    Supporting dynamic rule change with minimum packet loss is one of the key issues for intrusion detection. To detect intrusion, in general, Intrusion Detection System(IDS) has a copy step where P packet is captured at kernel level and it is used for detection in user level. While doing this job, the next packet cannot be captured because this procedure isn??t finished yet. This paper proposes the Kernel-level Intrusion Detection System(KIDS) which can detect various network attacks with minimum packet loss. This system is executed in kernel as a kernel program, and can detect intrusion at kernel level without copy step. Dynamic rule change is done quickly through appending and setting a delete mark operation. After this work, it is not needed to reboot a kernel and new type of network attack can be detected easily. With the help of this dynamic rule change, waiting time of detection process is minimized and its job can be continued as quickly as possible. Due to these features, the packet loss is greatly reduced.
  • Keywords
    Availability; Computer networks; Computer worms; Data security; Delta modulation; IP networks; Intrusion detection; Kernel; Protection; Web and internet services; Intrusion Detection System; kernel-level intrusion detection; signature-based detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Communication Technology, 2004. The 6th International Conference on
  • Conference_Location
    Phoenix Park, Korea
  • Print_ISBN
    89-5519-119-7
  • Type

    conf

  • DOI
    10.1109/ICACT.2004.1292859
  • Filename
    1292859