• DocumentCode
    998114
  • Title

    A Snort-based approach for the development and deployment of hybrid IDS

  • Author

    Diaz-Verdejo, Jesus E. ; Garcia-Teodoro, Pedro ; Munoz, Pascual ; Macia-Fernandez, Gabriel ; De Toro, F.

  • Volume
    5
  • Issue
    6
  • fYear
    2007
  • Firstpage
    386
  • Lastpage
    392
  • Abstract
    Apart from the modeling techniques, the development and deployment of anomaly-based intrusion detection systems still faces two main problems. The first one is related to the acquisition and handling of real traffic to be used for training purposes. The second one concerns the better performance of signature-based IDS for known attacks. In this paper the authors propose the use of a modified version of Snort which results in a hybrid detector/classifier. This version can be used both during the training phase of the anomaly-based system and as a deployed hybrid detector and traffic sniffer. Furthermore, it can be adjusted to work just as signature-based, anomaly-based or both (hybrid) detector. On the other hand, this version can be used to directly sniff, classify and split the network traffic according to its malicious nature, which eases the problems related to the acquisition and handling of training traffic.
  • Keywords
    Detectors; Internet; Intrusion detection; Law; Legal factors; Monitoring; Silicon compounds; Telecommunication standards; Computer network security; intrusion detection;
  • fLanguage
    English
  • Journal_Title
    Latin America Transactions, IEEE (Revista IEEE America Latina)
  • Publisher
    ieee
  • ISSN
    1548-0992
  • Type

    jour

  • DOI
    10.1109/TLA.2007.4395226
  • Filename
    4395226