DocumentCode
2901279
Title
Kernel-level intrusion detection system for minimum packet loss
Author
Bo-Heung Chung ; Jeong-Nyeo Kim ; Sung-Won Sohn ; Chee-hang Park
Author_Institution
Electronics and Telecommunications Research Institute(ETRI)
Volume
1
fYear
2004
fDate
9-11 Feb. 2004
Firstpage
207
Lastpage
212
Abstract
Supporting dynamic rule change with minimum packet loss is one of the key issues for intrusion detection. To detect intrusion, in general, Intrusion Detection System(IDS) has a copy step where P packet is captured at kernel level and it is used for detection in user level. While doing this job, the next packet cannot be captured because this procedure isn??t finished yet. This paper proposes the Kernel-level Intrusion Detection System(KIDS) which can detect various network attacks with minimum packet loss. This system is executed in kernel as a kernel program, and can detect intrusion at kernel level without copy step. Dynamic rule change is done quickly through appending and setting a delete mark operation. After this work, it is not needed to reboot a kernel and new type of network attack can be detected easily. With the help of this dynamic rule change, waiting time of detection process is minimized and its job can be continued as quickly as possible. Due to these features, the packet loss is greatly reduced.
Keywords
Availability; Computer networks; Computer worms; Data security; Delta modulation; IP networks; Intrusion detection; Kernel; Protection; Web and internet services; Intrusion Detection System; kernel-level intrusion detection; signature-based detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Communication Technology, 2004. The 6th International Conference on
Conference_Location
Phoenix Park, Korea
Print_ISBN
89-5519-119-7
Type
conf
DOI
10.1109/ICACT.2004.1292859
Filename
1292859
Link To Document