• DocumentCode
    2176051
  • Title

    A DoS Resilient Flow-level Intrusion Detection Approach for High-speed Networks

  • Author

    Gao, Yan ; Li, Zhichun ; Chen, Yan

  • Author_Institution
    Northwestern Univ
  • fYear
    2006
  • fDate
    2006
  • Firstpage
    39
  • Lastpage
    39
  • Abstract
    Global-scale attacks like viruses and worms are increasing in frequency, severity and sophistication, making it critical to detect outbursts at routers/gateways instead of end hosts. In this paper we leverage data streaming techniques such as the reversible sketch to obtain HiFIND, a High-speed Flow-level Intrusion Detection system. In contrast to existing intrusion detection systems, HiFIND I ) is scalable to flow-level detection on high-speed networks; 2) zs DoS resilient; 3) can distinguish SYN flooding and various port scans (mostly for worm propagation) for effective mitigation; 4 ) enables aggregate detection over multiple routers/gateways; and 5) separates anomalies to limit false positives in detection. Both theoretical analysis and evaluation with several router traces show that HiFIND achieves these properties. To the best of our knowledge, HiFIND is the first online DoS resilient flow-level intrusion detection system for high-speed networks (approximately 10s of Gigabit/second), even for the worst case trafic of 40-byte-packet streams with each packet forming a flow.
  • Keywords
    Aggregates; Bandwidth; Frequency; Hardware; High-speed networks; Intrusion detection; Routing; Scalability; Telecommunication traffic; Viruses (medical);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems, 2006. ICDCS 2006. 26th IEEE International Conference on
  • ISSN
    1063-6927
  • Print_ISBN
    0-7695-2540-7
  • Type

    conf

  • DOI
    10.1109/ICDCS.2006.6
  • Filename
    1648826