• DocumentCode
    2262361
  • Title

    On network intrusion detection for deployment in the wild

  • Author

    Kim, Sun-il ; Nwanze, Nnamdi ; Edmonds, William ; Johnson, Blake ; Field, Paloma

  • Author_Institution
    Electr. & Comput. Syst. Eng., Univ. of Alaska Anchorage, Anchorage, AK, USA
  • fYear
    2012
  • fDate
    16-20 April 2012
  • Firstpage
    253
  • Lastpage
    260
  • Abstract
    As the number of network-based attacks continue to increase, network operations and management tasks become more and more complex. As we have come to depend on reliable operations of networked systems, it is important to be able to provide security measures that both efficient in terms of processing speed as well as in detecting attacks that are not in the database. To this end, anomaly-based intrusion detection systems allow detection of previously unknown and never seen attacks, and effectively complement signature-based detection schemes. In this paper, we evaluate a robust intrusion detection scheme with the goal of developing stand-alone devices that can be deployed in a plug-and-play manner to existing systems. Such devices are attractive as it allows an added security feature to quickly be deployed without adding to the management complexity of existing systems. Our system is robust in that it is resilient to contaminated traffic that may be included in real-time training. Leveraging this advantage, we show that our detection system can self-train without the need for a large, sanitized training data set typically required for many anomaly-based detection schemes. This feature naturally lends itself to faster deployment and for managing systems in changing environments. We demonstrate this concept by developing a physical prototype using an embedded platform. Our results show that amount of delay introduced by the device is small. Another attractive feature of the stand alone device is that it is impossible to temper with without physical access to the device, even if host systems are compromised.
  • Keywords
    Internet; computer network management; computer network security; Internet; anomaly-based intrusion detection systems; complement signature-based detection schemes; embedded platform; management complexity; network intrusion detection; network management tasks; network-based attacks; networked systems; real-time training; sanitized training data set; stand-alone devices; Delay; Intrusion detection; Payloads; Prototypes; Training; Tuning;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (NOMS), 2012 IEEE
  • Conference_Location
    Maui, HI
  • ISSN
    1542-1201
  • Print_ISBN
    978-1-4673-0267-8
  • Electronic_ISBN
    1542-1201
  • Type

    conf

  • DOI
    10.1109/NOMS.2012.6211906
  • Filename
    6211906