DocumentCode :
998114
Title :
A Snort-based approach for the development and deployment of hybrid IDS
Author :
Diaz-Verdejo, Jesus E. ; Garcia-Teodoro, Pedro ; Munoz, Pascual ; Macia-Fernandez, Gabriel ; De Toro, F.
Volume :
5
Issue :
6
fYear :
2007
Firstpage :
386
Lastpage :
392
Abstract :
Apart from the modeling techniques, the development and deployment of anomaly-based intrusion detection systems still faces two main problems. The first one is related to the acquisition and handling of real traffic to be used for training purposes. The second one concerns the better performance of signature-based IDS for known attacks. In this paper the authors propose the use of a modified version of Snort which results in a hybrid detector/classifier. This version can be used both during the training phase of the anomaly-based system and as a deployed hybrid detector and traffic sniffer. Furthermore, it can be adjusted to work just as signature-based, anomaly-based or both (hybrid) detector. On the other hand, this version can be used to directly sniff, classify and split the network traffic according to its malicious nature, which eases the problems related to the acquisition and handling of training traffic.
Keywords :
Detectors; Internet; Intrusion detection; Law; Legal factors; Monitoring; Silicon compounds; Telecommunication standards; Computer network security; intrusion detection;
fLanguage :
English
Journal_Title :
Latin America Transactions, IEEE (Revista IEEE America Latina)
Publisher :
ieee
ISSN :
1548-0992
Type :
jour
DOI :
10.1109/TLA.2007.4395226
Filename :
4395226
Link To Document :
بازگشت