DocumentCode :
3142809
Title :
Towards real-time intrusion detection for NetFlow and IPFIX
Author :
Hofstede, Rick ; Bartos, Vaclav ; Sperotto, Anna ; Pras, Aiko
Author_Institution :
Centre for Telematics & Inf. Technol. (CTIT), Univ. of Twente, Enschede, Netherlands
fYear :
2013
fDate :
14-18 Oct. 2013
Firstpage :
227
Lastpage :
234
Abstract :
DDoS attacks bring serious economic and technical damage to networks and enterprises. Timely detection and mitigation are therefore of great importance. However, when flow monitoring systems are used for intrusion detection, as it is often the case in campus, enterprise and backbone networks, timely data analysis is constrained by the architecture of NetFlow and IPFIX. In their current architecture, the analysis is performed after certain timeouts, which generally delays the intrusion detection for several minutes. This paper presents a functional extension for both NetFlow and IPFIX flow exporters, to allow for timely intrusion detection and mitigation of large flooding attacks. The contribution of this paper is threefold. First, we integrate a lightweight intrusion detection module into a flow exporter, which moves detection closer to the traffic observation point. Second, our approach mitigates attacks in near real-time by instructing firewalls to filter malicious traffic. Third, we filter flow data of malicious traffic to prevent flow collectors from overload. We validate our approach by means of a prototype that has been deployed on a backbone link of the Czech national research and education network CESNET.
Keywords :
IP networks; computer network security; telecommunication traffic; CESNET; Czech national research and education network; DDoS attack; IPFIX; NetFlow; flooding attack; flow monitoring system; lightweight intrusion detection; malicious traffic; real-time intrusion detection; Accuracy; Delays; Detection algorithms; Forecasting; Intrusion detection; Prototypes; Denial of service; Flow monitoring; IPFIX; Internet measurements; Intrusion detection; NetFlow;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and Service Management (CNSM), 2013 9th International Conference on
Conference_Location :
Zurich
Type :
conf
DOI :
10.1109/CNSM.2013.6727841
Filename :
6727841
Link To Document :
بازگشت