Dynamical analysis of diversity in rule-based open source network intrusion detection systems

Dynamical analysis of diversity in rule-based open source network intrusion detection systems
复制标题

基于规则的开源网络入侵检测系统多样性的动态分析

DOI:
10.1007/s10664-021-10046-w
复制
发表时间:
2021
影响因子:
4.1
通讯作者:
Asad H
Asad H
中科院分区:
计算机科学2区
文献类型:
--
作者:
Asad H

文献摘要

参考文献

被引文献

相似文献

不同的防御层在纵深防御体系结构的设计中起着重要的作用。在这种设计中,入侵检测系统(ids)的使用无处不在。但是,在各种配置中选择“正确”的ids是安全架构师需要做出的重要决策。此外,还需要调查这些入侵防御系统适应不断变化的威胁形势的能力。为了帮助做出这些决定,我们需要严格的定量分析。在本文中,我们对开源ids、Snort和Suricata进行了多样性分析,以帮助安全架构师调优/部署这些ids。我们分析了这些IDSs的两种类型的多样性;结构多样性和功能多样性。在配置多样性分析中,我们研究了这些ids在其配置中使用的规则集和黑名单IP地址(bipa)的多样性。功能多样性分析研究了这些入侵防御系统在分析真实网络流量时警报行为的差异,以及这些差异如何演变。配置多样性实验利用了2017年5月至10月5个月期间收集的规则和bipa的快照。这些快照是针对Snort IDS的三种现成默认配置和Suricata IDS的新兴威胁(Emerging Threats, ET)配置收集的。功能多样性研究了这两个ids在同一时间窗口内收集的真实网络流量样本的警报行为。分析这些系统的差异使我们能够深入了解这些系统行为的多样性来自哪里,它是如何演变的,以及这是否对这些ids的警报行为有任何影响。此分析使安全架构师了解如何在纵深防御部署中组合和分层这些系统。
Diverse layers of defence play an important role in the design of defence-in-depth architectures. The use of Intrusion Detection Systems (IDSs) are ubiquitous in this design. But the selection of the “right” IDSs in various configurations is an important decision that the security architects need to make. Additionally, the ability of these IDSs to adapt to the evolving threat-landscape also needs to be investigated. To help with these decisions, we need rigorous quantitative analysis. In this paper, we present a diversity analysis of open-source IDSs, Snort and Suricata, to help security architects tune/deploy these IDSs. We analyse two types of diversities in these IDSs; configurational diversity and functional diversity. In the configurational diversity analysis, we investigate the diversity in the sets of rules and the Blacklisted IP Addresses (BIPAs) these IDSs use in their configurations. The functional diversity analysis investigates the differences in alerting behaviours of these IDSs when they analyse real network traffic, and how these differences evolve. The configurational diversity experiment utilises snapshots of the rules and BIPAs collected over a period of 5 months, from May to October 2017. The snapshots have been collected for three different off-the-shelf default configurations of the Snort IDS and the Emerging Threats (ET) configuration of the Suricata IDS. The functional diversity investigates the alerting behaviour of these two IDSs for a sample of the real network traffic collected in the same time window. Analysing the differences in these systems allows us to get insights into where the diversity in the behaviour of these systems comes from, how does it evolve and whether this has any effect on the alerting behaviour of these IDSs. This analysis gives insight to security architects on how they can combine and layer these systems in a defence-in-depth deployment.
DOI: --
发表时间: 2020
影响因子: 5.6
作者:
Qinwen Hu;Se;M. R. Asghar
通讯作者: M. R. Asghar
三种入侵检测系统在不同攻击和规则集下的评估研究
DOI: --
发表时间: 2013
期刊: IEEE Region 10 Conference
影响因子: --
作者:
Kittikhun Thongkanchorn;S. Ngamsuriyaroj;V. Visoottiviseth
通讯作者: V. Visoottiviseth
Linux与Windows Server下Snort NIDS性能评估对比
DOI: --
发表时间: 2010
影响因子: 8.7
作者:
K. Salah;A. Kahtani
通讯作者: A. Kahtani
入侵检测系统的多样性:实证研究
DOI: 10.1109/nca.2017.8171327
发表时间: 2017
期刊: --
影响因子: --
作者:
Algaith A
通讯作者: Algaith A
DOI: 10.1002/spe.2180
发表时间: 2014
期刊: Software: Practice and Experience
影响因子: --
作者:
Miguel Garcia;A. Bessani;Ilir Gashi;Nuno Ferreira Neves;R. Obelheiro
通讯作者: R. Obelheiro