White Papers

A DoS Resilient Flow-Level Intrusion Detection Approach for High-Speed Networks

Category: Security

Tags: false positives, routers, data

Overview Global-scale attacks like viruses and worms are increasing in frequency, severity and sophistication, making it critical to detect outbursts at routers/gateways instead of end hosts. This paper leverages data streaming techniques such as the reversible sketch to obtain HiFIND, a High-speed Flow-level Intrusion Detection system. In contrast to existing intrusion detection systems, HiFIND is scalable to low-level detection on high-speed networks; HiFIND is DoS resilient; HiFIND can distinguish SYN flooding and various port scans (mostly for worm propagation) for effective mitigation; HiFIND enables aggregate detection over multiple routers/gateways; and HiFIND separates anomalies to limit false positives in detection. Both theoretical analysis and evaluation with several router traces show that HiFIND achieves these properties.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Northwestern University
File Format
PDF
Date Published
Oct 14, 2008
Format
White Papers
Topics
Intrusion Detection Systems, Denial of Service, Network Security

Similiar White Papers

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

The X-Force Threat Insight Quarterly (Threat IQ) highlights the most significant threats and challenges facing security

Publisher: Internet Security Systems  |  Tags: homeland security, security flaws, voip

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

This technical product evaluation is focused on the ISS VoIP-enabled Intrusion Prevention devices. These are built to su

Publisher: Internet Security Systems  |  Tags: voip

Jargon, jargon, jargon. Find out what the IT industries acronyms really mean

Jargon, jargon, jargon. Find out what the IT industries acronyms really mean

ISS provide you with a simple glossary of major VoIP terms. What do they really mean, when can they be used? Make yourse

Publisher: Internet Security Systems  |  Tags: voip

IT's New Role: Defining and Managing Risk

IT's New Role: Defining and Managing Risk

This article explores how a Security Risk Management (SRM) approach can protect your company from the most severe threat

Publisher: McAfee  |  Tags: srm

ESG Report: Symantec Sets a Course for Security Leadership with Security 2.0

ESG Report: Symantec Sets a Course for Security Leadership with Security 2.0

Download this Enterprise Strategy Group (ESG) Security Brief to read about Symantec's recent rollout of its newest enter

Publisher: Symantec

Northwestern University White Papers

An Application of Central Limit Theorem to Wide Area Network Service Level Agreement Analyses

An Application of Central Limit Theorem to Wide Area Network Service Level Agreement Analyses

Managed Network Service Providers (NSP) supply the bandwidth, transport, equipment, and management services to connect d

Publisher: Northwestern University  |  Tags: management, wan

Towards a High-Speed Router-Based Anomaly/Intrusion Detection System

Towards a High-Speed Router-Based Anomaly/Intrusion Detection System

Traffic anomalies and attacks are commonplace in today's networks, and identifying them rapidly and accurately is critic

Publisher: Northwestern University  |  Tags: network, routers, the link

IDGraphs: Intrusion Detection and Analysis Using Histographs

IDGraphs: Intrusion Detection and Analysis Using Histographs

Traffic anomalies and attacks are commonplace in today's networks and identifying them rapidly and accurately is critica

Publisher: Northwestern University  |  Tags: network, routers

Performance Evaluation and Characterization of Scalable Data Mining Algorithms

Performance Evaluation and Characterization of Scalable Data Mining Algorithms

Data mining has become one of the most essential tools in diverse fields. The increases in data sizes and algorithmic co

Publisher: Northwestern University  |  Tags: applications, benchmark, benchmarking, data, data mining, software

Reverse Hashing for High-Speed Network Monitoring: Algorithms, Evaluation, and Applications

Reverse Hashing for High-Speed Network Monitoring: Algorithms, Evaluation, and Applications

A key function for network traffic monitoring and analysis is the ability to perform aggregate queries over multiple dat

Publisher: Northwestern University  |  Tags: data, ip, network