• DocumentCode
    3523432
  • Title

    Experimental Validation of An Intelligent Detection and Response Strategy for Complex Infrastructure Attacks and False Positives Using Firewalls

  • Author

    Hooper, Emmanuel

  • Author_Institution
    Inf. Security Group, London Univ., Surrey
  • fYear
    2006
  • fDate
    Oct. 2006
  • Firstpage
    252
  • Lastpage
    256
  • Abstract
    The current intrusion detection systems (IDS) which attempt to identify suspicious network traffic have major limitations. The high percentage of alerts generated by such systems, the level of false positives is one of the major problems. We present intelligent strategies for reduction of false positives and infrastructure protection using a novel approach using adaptive responses from multiple firewalls and VPNs (virtual private networks) rule sets in a novel "network quarantine channels" (NQC), using firewall architectures. The focus of this paper is on firewall rule sets which operate within the NQC to respond to suspicious hosts and then deny access to critical segments of the network infrastructure. The firewall rule sets provide effective intelligent responses by granting access to the normal packets and denying malicious traffic access to the network, after the identity of the connections are verified through the statistical analysis in the NQC. These effective strategies reduce false positives and increases detection capability of the IDS
  • Keywords
    authorisation; computer networks; telecommunication security; virtual private networks; complex infrastructure attacks; false positives; firewall rule sets; intelligent detection and response strategy; intrusion detection systems; network infrastructure security; network quarantine channels; statistical analysis; virtual private networks; Complex networks; Information security; Intelligent networks; Intrusion detection; Monitoring; Protection; Statistical analysis; Telecommunication traffic; Virtual manufacturing; Virtual private networks; false positives; firewalls; intrusion detection and response; network infrastructure security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Carnahan Conferences Security Technology, Proceedings 2006 40th Annual IEEE International
  • Conference_Location
    Lexington, KY
  • Print_ISBN
    1-4244-0174-7
  • Type

    conf

  • DOI
    10.1109/CCST.2006.313458
  • Filename
    4105345