An Overview of IP Flow-Based Intrusion Detection

An Overview of IP Flow-Based Intrusion Detection
复制标题

DOI:
10.1109/surv.2010.032210.00054
复制
发表时间:
2010-01-01
影响因子:
35.6
通讯作者:
Stiller, Burkhard
Stiller, Burkhard
中科院分区:
计算机科学1区
文献类型:
--
作者:
Sperotto, Anna;Schaffrath, Gregor;Stiller, Burkhard

文献摘要

被引文献

相似文献

入侵检测是一个重要的研究领域。传统上,发现攻击的方法是检查每个数据包的内容。然而,数据包检测在高速下很难实现。因此,研究人员和运营商开始研究替代方法,例如基于流的入侵检测。在这种方法中,通过网络的数据流被分析,而不是每个数据包的内容。本文的目的是对基于流的入侵检测的研究现状进行综述。调查从为什么需要基于流的入侵检测的动机开始。解释了流的概念,并确定了相关标准。本文提供了攻击和防御技术的分类,并展示了如何使用基于流的技术来检测扫描,蠕虫,僵尸网络和拒绝服务(DoS)攻击。
Intrusion detection is an important area of research. Traditionally, the approach taken to find attacks is to inspect the contents of every packet. However, packet inspection cannot easily be performed at high-speeds. Therefore, researchers and operators started investigating alternative approaches, such as flow-based intrusion detection. In that approach the flow of data through the network is analyzed, instead of the contents of each individual packet.The goal of this paper is to provide a survey of current research in the area of flow-based intrusion detection. The survey starts with a motivation why flow-based intrusion detection is needed. The concept of flows is explained, and relevant standards are identified. The paper provides a classification of attacks and defense techniques and shows how flow-based techniques can be used to detect scans, worms, Botnets and Denial of Service (DoS) attacks.