Stateful Intrusion Detection for High-Speed Networks

  • Authors:
  • Christopher Kruegel;Fredrik Valeur;Giovanni Vigna;Richard Kemmerer

  • Affiliations:
  • -;-;-;-

  • Venue:
  • SP '02 Proceedings of the 2002 IEEE Symposium on Security and Privacy
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

As networks become faster there is an emerging need for security analysistechniques that can keep up with the increased network throughput. Existingnetwork-based intrusion detection sensors can barely keep up withbandwidthsof a few hundred Mbps. Analysis tools that can deal with higher throughputareunable to maintain state between different steps of an attack or they arelimited to the analysis of packet headers. We propose a partitioningapproachto network security analysis that supports in-depth, stateful intrusiondetection on high-speed links. The approach is centered around a "slicing"mechanism that divides the overall network traffic into subsets ofmanageablesize. The traffic partitioning is done so that a single slice contains alltheevidence necessary to detect a specific attack, making sensor-to-sensorinteractions unnecessary. This paper describes the approach and presents afirst experimental evaluation of its effectiveness.