Title :
Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detection
Author :
Meng, Yuxin ; Kwok, Lam-for
Author_Institution :
Comput. Sci. Dept., City Univ. of Hong Kong, Hong Kong, China
Abstract :
By using string matching, signature-based network intrusion detection systems (NIDSs) can achieve a higher accuracy and lower false alarm rate than the anomaly-based systems. But the matching process is very expensive regarding to the performance of a signature-based NIDS in which the cost is at least linear to the size of the input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem greatly limits the high performance of a signature-based NIDS in a large operational network. In this paper, we present a context-aware packet filter scheme aiming to mitigate this problem. In particular, our scheme incorporates a list technique, namely the blacklist to help filter network packets based on the confidence of the IP domains. Moreover, our scheme will adapt and update the blacklist contents by using the method of statistic-based blacklist generation according to the actual network environment. In the experiment, we implemented our scheme and showed the first experimental evaluation of its effectiveness.
Keywords :
IP networks; security of data; statistical analysis; string matching; CPU occupancy rate; IP domains; adaptive context-aware packet filter scheme; false alarm rate; signature-based network intrusion detection system; statistic-based blacklist generation; string matching; Engines; IP networks; Intrusion detection; Monitoring; Payloads; Table lookup; blacklist; intrusion detection; network packet filter;
Conference_Titel :
Information Assurance and Security (IAS), 2011 7th International Conference on
Conference_Location :
Melaka
Print_ISBN :
978-1-4577-2154-0
DOI :
10.1109/ISIAS.2011.6122798