Enhancing the accuracy of network-based intrusion detection with host-based context

  • Authors:
  • Holger Dreger;Christian Kreibich;Vern Paxson;Robin Sommer

  • Affiliations:
  • Computer Science Department, Technische Universität München;Computer Laboratory, University of Cambridge;International Computer Science Institute and Lawrence Berkeley National Laboratory;Computer Science Department, Technische Universität München

  • Venue:
  • DIMVA'05 Proceedings of the Second international conference on Detection of Intrusions and Malware, and Vulnerability Assessment
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In the recent past, both network- and host-based approaches to intrusion detection have received much attention in the network security community. No approach, taken exclusively, provides a satisfactory solution: network-based systems are prone to evasion, while host-based solutions suffer from scalability and maintenance problems. In this paper we present an integrated approach, leveraging the best of both worlds: we preserve the advantages of network-based detection, but alleviate its weaknesses by improving the accuracy of the traffic analysis with specific host-based context. Our framework preserves a separation of policy from mechanism, is highly configurable and more flexible than sensor/manager-based architectures, and imposes a low overhead on the involved end hosts. We include a case study of our approach for a notoriously hard problem for purely network-based systems: the correct processing of HTTP requests.