Title :
Kernel-level intrusion detection system for minimum packet loss
Author :
Bo-Heung Chung ; Jeong-Nyeo Kim ; Sung-Won Sohn ; Chee-hang Park
Author_Institution :
Electronics and Telecommunications Research Institute(ETRI)
Abstract :
Supporting dynamic rule change with minimum packet loss is one of the key issues for intrusion detection. To detect intrusion, in general, Intrusion Detection System(IDS) has a copy step where P packet is captured at kernel level and it is used for detection in user level. While doing this job, the next packet cannot be captured because this procedure isn??t finished yet. This paper proposes the Kernel-level Intrusion Detection System(KIDS) which can detect various network attacks with minimum packet loss. This system is executed in kernel as a kernel program, and can detect intrusion at kernel level without copy step. Dynamic rule change is done quickly through appending and setting a delete mark operation. After this work, it is not needed to reboot a kernel and new type of network attack can be detected easily. With the help of this dynamic rule change, waiting time of detection process is minimized and its job can be continued as quickly as possible. Due to these features, the packet loss is greatly reduced.
Keywords :
Availability; Computer networks; Computer worms; Data security; Delta modulation; IP networks; Intrusion detection; Kernel; Protection; Web and internet services; Intrusion Detection System; kernel-level intrusion detection; signature-based detection;
Conference_Titel :
Advanced Communication Technology, 2004. The 6th International Conference on
Conference_Location :
Phoenix Park, Korea
Print_ISBN :
89-5519-119-7
DOI :
10.1109/ICACT.2004.1292859