DocumentCode :
3144622
Title :
Intrusion analysis with deep packet inspection: Increasing efficiency of packet based investigations
Author :
Smallwood, Daniel ; Vance, Andrew
Author_Institution :
Comput. Sci. Corp., Falls Church, VA, USA
fYear :
2011
fDate :
12-14 Dec. 2011
Firstpage :
342
Lastpage :
347
Abstract :
Cloud computing´s distributed architecture helps ensure service resilience and robustness. However, cloud architectures also increase dynamic data communications which inherently increases security risks. Examination of industry practice has revealed that increased data volume, as a result of increased communication, diminishes the efficiency of deep packet inspections (DPI). DPI is essential in protecting the cloud against malicious threats such as web exploits, zeroday attacks, data exfiltration, and malware based botnets. In this paper, we evaluate the effectiveness of a new utility that was developed to improve retrospective packet analysis which was tested against actual data center traffic from a large regional Internet Access Provider providing cloud services. Blitzdump is a lightning fast network data packet capture utility developed to improve network intrusion detection through deep packet inspection analysis. Implementation results indicate it outperformed existing techniques, in terms of query function performance, that ultimately improved efficiency in query responses by up to 6000%. Blitzdump reduces security risks by increasing the technical performance of intrusion detection to improve the security practitioner´s productivity and effectiveness.
Keywords :
Internet; computer network security; Cloud computing distributed architecture; DPI; Internet access provider; data communications; data exfiltration; data volume; deep packet inspection; intrusion analysis; malicious threats; malware based botnets; packet based investigations; query function; web exploits; zeroday attacks; Cloud computing; Inspection; Intrusion detection; Linux; Sensors; Cloud Computing; Deep Packet Inspection; Intrusion Detection; Packet Capture; Security; TCPDUMP;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud and Service Computing (CSC), 2011 International Conference on
Conference_Location :
Hong Kong
Print_ISBN :
978-1-4577-1635-5
Electronic_ISBN :
978-1-4577-1636-2
Type :
conf
DOI :
10.1109/CSC.2011.6138545
Filename :
6138545
Link To Document :
بازگشت