DocumentCode :
1626271
Title :
A comprehensive network intrusion detection and prevention system architecture
Author :
Mirpuryan, M.S. ; Tavizi, T. ; Gharaee, Hossein
Author_Institution :
Dept. of ICT Security, Iran Telecom Res. Center (ITRC), Tehran, Iran
fYear :
2012
Firstpage :
954
Lastpage :
958
Abstract :
In today´s computing environments, Network Intrusion Detection and Prevention Systems (NIDPS) are one of the fundamental network components to monitor and analyze traffic to find possible attacks. Several works have been done to introduce an applicable NIDPS architecture, but none of them could cover all current NIDPS requirements. In this paper we will present a comprehensive architecture for NIDPS which is comprised of the main components and the data flow between them. This architecture consists of all NIDPS components including capture and decoding module, preprocessing, detection, response and management. The detection module will cover both misuse based and anomaly based approaches. Moreover, anomaly based detection module includes traffic and protocol anomaly detection as well as learning based approaches. The proposed architecture is designed to perform in four modes of operation: passive response mode, active response mode, fast prevention mode, and perfect prevention mode. Moreover, it is capable to work in high speed networks due to the existence of fast prevention mode. We also designed a complete management module for NIDPS which provides more useful functionalities in relation with the other modules to help them to operate in a proper manner.
Keywords :
computer network security; telecommunication traffic; NIDPS architecture; active response mode; anomaly based approach; anomaly based detection module; capture module; decoding module; fast prevention mode; learning based approach; misuse based approach; network intrusion detection; network intrusion prevention system; passive response mode; perfect prevention mode; protocol anomaly detection; traffic anomaly detection; Authentication; Computer architecture; Databases; Decoding; Intrusion detection; Protocols; Active Response; Management; NIDPS; Prevention;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Telecommunications (IST), 2012 Sixth International Symposium on
Conference_Location :
Tehran
Print_ISBN :
978-1-4673-2072-6
Type :
conf
DOI :
10.1109/ISTEL.2012.6483124
Filename :
6483124
Link To Document :
بازگشت