Title :
Experimental Validation of An Intelligent Detection and Response Strategy for Complex Infrastructure Attacks and False Positives Using Firewalls
Author :
Hooper, Emmanuel
Author_Institution :
Inf. Security Group, London Univ., Surrey
Abstract :
The current intrusion detection systems (IDS) which attempt to identify suspicious network traffic have major limitations. The high percentage of alerts generated by such systems, the level of false positives is one of the major problems. We present intelligent strategies for reduction of false positives and infrastructure protection using a novel approach using adaptive responses from multiple firewalls and VPNs (virtual private networks) rule sets in a novel "network quarantine channels" (NQC), using firewall architectures. The focus of this paper is on firewall rule sets which operate within the NQC to respond to suspicious hosts and then deny access to critical segments of the network infrastructure. The firewall rule sets provide effective intelligent responses by granting access to the normal packets and denying malicious traffic access to the network, after the identity of the connections are verified through the statistical analysis in the NQC. These effective strategies reduce false positives and increases detection capability of the IDS
Keywords :
authorisation; computer networks; telecommunication security; virtual private networks; complex infrastructure attacks; false positives; firewall rule sets; intelligent detection and response strategy; intrusion detection systems; network infrastructure security; network quarantine channels; statistical analysis; virtual private networks; Complex networks; Information security; Intelligent networks; Intrusion detection; Monitoring; Protection; Statistical analysis; Telecommunication traffic; Virtual manufacturing; Virtual private networks; false positives; firewalls; intrusion detection and response; network infrastructure security;
Conference_Titel :
Carnahan Conferences Security Technology, Proceedings 2006 40th Annual IEEE International
Conference_Location :
Lexington, KY
Print_ISBN :
1-4244-0174-7
DOI :
10.1109/CCST.2006.313458