首页    期刊浏览 2024年09月20日 星期五
登录注册

文章基本信息

  • 标题:Towards Multi-Stage Intrusion Detection using IP Flow Records
  • 本地全文:下载
  • 作者:Muhammad Fahad Umer ; Muhammad Sher ; Imran Khan
  • 期刊名称:International Journal of Advanced Computer Science and Applications(IJACSA)
  • 印刷版ISSN:2158-107X
  • 电子版ISSN:2156-5570
  • 出版年度:2016
  • 卷号:7
  • 期号:10
  • DOI:10.14569/IJACSA.2016.071046
  • 出版社:Science and Information Society (SAI)
  • 摘要:Traditional network-based intrusion detection sys-tems using deep packet inspection are not feasible for modern high-speed networks due to slow processing and inability to read encrypted packet content. As an alternative to packet-based intrusion detection, researchers have focused on flow-based intrusion detection techniques. Flow-based intrusion detection systems analyze IP flow records for attack detection. IP flow records contain summarized traffic information. However, flow data is very large in high-speed networks and cannot be processed in real-time by the intrusion detection system. In this paper, an efficient multi-stage model for intrusion detection using IP flows records is proposed. The first stage in the model classifies the traffic as normal or malicious. The malicious flows are further analyzed by a second stage. The second stage associates an attack type with malicious IP flows. The proposed multi-stage model is efficient because the majority of IP flows are discarded in the first stage and only malicious flows are examined in detail. We also describe the implementation of our model using machine learning techniques.
  • 关键词:thesai; IJACSA Volume 7 Issue 10; IP flows; Multi-stage intrusion detection; One-class classification; Multi-class classification
国家哲学社会科学文献中心版权所有