Performance Oriented Dynamic Bypassing for Intrusion Detection Systems

Performance Oriented Dynamic Bypassing for Intrusion Detection Systems
复制标题

入侵检测系统的面向性能的动态旁路

DOI:
10.1145/3297663.3310313
复制
发表时间:
2019
期刊:
Proceedings of the 2019 ACM/SPEC International Conference on Performance Engineering
影响因子:
--
通讯作者:
Samuel Kounev
Samuel Kounev
中科院分区:
--
文献类型:
--
作者:
Lukas Iffländer;Jonathan Stoll;Nishant Rawtani;Veronika Lesch;Klaus-Dieter Lange;Samuel Kounev

文献摘要

参考文献

被引文献

相似文献

对软件系统的攻击正变得越来越频繁、侵略性和复杂。随着威胁形势的不断变化,在2018年,组织正在关注他们何时会受到攻击,而不是如果。入侵检测系统(IDS)可以帮助防御这些攻击。入侵检测系统的主机系统需要大量的计算资源,因为入侵检测系统往往会错误地检测过载条件下的攻击。随着摩尔定律的终结和物联网的日益普及,安全系统的设计人员再也不能指望处理能力跟上他们的步伐。这种限制要求在不增加额外计算能力的情况下提高这些系统的性能。在这项工作中,我们提出了两个动态和静态的方法来绕过IDS的流量被认为是良性的。我们提供其原型实现并评估我们的解决方案。我们的评估显示了有希望的结果。性能提高到没有IDS的系统的水平。攻击检测在100%的误差范围内。然而,我们的研究结果表明,动态方法在使用软件交换机时表现最好。硬件开关的使用显著降低了检测速率和性能。
Attacks on software systems are becoming more and more frequent, aggressive and sophisticated. With the changing threat landscape, in 2018, organizations are looking at when they will be attacked, not if. Intrusion Detection Systems (IDSs) can help in defending against these attacks. The systems that host IDSs require extensive computing resources as IDSs tend to detect attacks under overloaded conditions wrongfully. With the end of Moore's law and the growing adoption of Internet of Things, designers of security systems can no longer expect processing power to keep up the pace with them. This limitation requires ways to increase the performance of these systems without adding additional compute power. In this work, we present two dynamic and a static approach to bypass IDS for traffic deemed benign. We provide its prototype implementation and evaluate our solution. Our evaluation shows promising results. Performance is increased up to the level of a system without an IDS. Attack detection is within the margin of error from the 100% rate. However, our findings show that dynamic approaches perform best when using software switches. The use of a hardware switch reduces the detection rate and performance significantly.
调查 IDS 误报问题:使用 Snort 的实验研究
DOI: --
发表时间: 2008
期刊: IFIP International Information Security Conference
影响因子: --
作者:
Gina C. Tjhai;M. Papadaki;S. Furnell;N. Clarke
通讯作者: N. Clarke
Snort 在 DARPA 数据集上的性能和不同的误报减少技术
DOI: --
发表时间: 2016
期刊:
影响因子: --
作者:
Ayushi Chahal;Ritu Nagpal
通讯作者: Ritu Nagpal
DOI: --
发表时间: 2003
期刊: International Symposium on Recent Advances in Intrusion Detection
影响因子: --
作者:
Lambert Schaelicke;Thomas Slabach;Branden J. Moore;C. Freeland
通讯作者: C. Freeland
DOI: 10.1109/mcom.2014.6829966
发表时间: 2014-06-01
影响因子: 11.2
作者:
Jarschel, Michael;Zinner, Thomas;Kellerer, Wolfgang
通讯作者: Kellerer, Wolfgang
DOI: --
发表时间: 2011
期刊: ANT/MobiWIS
影响因子: --
作者:
Adeeb M. Alhomoud;Rashid Munir;J. Disso;I. Awan;A. Al
通讯作者: A. Al