DocumentCode
3308348
Title
Architecture of the reconnaissance intrusion detection system (RIDS)
Author
Zhang, Zheng ; Manikopoulos, Constantine N.
Author_Institution
Electr. & Comput. Eng. Dept., New Jersey Inst. of Technol., Newark, NJ, USA
fYear
2004
fDate
10-11 June 2004
Firstpage
187
Lastpage
194
Abstract
This paper describes the architecture and provides early test results of the reconnaissance intrusion detection system (RIDS) prototype. RIDS is a session oriented, statistical tool, that relies on training to mold the parameters of its algorithms, capable of detecting even distributed stealthy reconnaissance attacks. It consists of two main functional modules or stages: the reconnaissance activity profiler (RAP), followed by the reconnaissance alert correlation (RAC), along with a security console. RAP is a session-oriented module capable of detecting stealthy scanning and probing attacks, while RAC is an alert-correlation module that fuses the RAP alerts into attack scenarios and discovers the distributed stealthy attack scenarios, RIDS has been evaluated against two data sets: (a) the DARPA´98 data, and (b) 3 weeks of experimental data generated using the CONEX testbed, running at average Ethernet speeds. RIDS has demonstrably achieved remarkable success; the false positive, false negative and misclassification rates found are low, less than 0.1%, for most reconnaissance attacks; they rise to about 6% for distributed highly stealthy attacks; the latter is a most challenging type of attack, which has been difficult to detect effectively until now. Thus, the RIDS system promises to provide an early warning by detecting the reconnaissance first phase of an impending attack, even if it is very stealthy and distributed.
Keywords
security of data; system monitoring; alert correlation; anomaly detection; distributed stealthy reconnaissance attack; reconnaissance intrusion detection system; session oriented statistical tool; Data security; Ethernet networks; Fuses; Intrusion detection; Phase detection; Prototypes; Reconnaissance; Senior members; Student members; System testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance Workshop, 2004. Proceedings from the Fifth Annual IEEE SMC
Print_ISBN
0-7803-8572-1
Type
conf
DOI
10.1109/IAW.2004.1437816
Filename
1437816
Link To Document