EEMCS

Home > Publications
Home University of Twente
Education
Research
Prospective Students
Jobs
Publications
Intranet (internal)
 
 Nederlands
 Contact
 Search
 Organisation

EEMCS EPrints Service


21998 Real-Time and Resilient Intrusion Detection: A Flow-Based Approach
Home Policy Brochure Browse Search User Area Contact Help

Hofstede, R.J. and Pras, A. (2012) Real-Time and Resilient Intrusion Detection: A Flow-Based Approach. In: Proceedings of the 6th International Conference on Autonomous Infrastructure, Management, and Security (AIMS 2012), 4-8 Jun 2012, Luxembourg, Luxembourg. pp. 109-112. Lecture Notes in Computer Science 7279. Springer Verlag. ISSN 0302-9743 ISBN 978-3-642-30632-7

Full text available as:

PDF

266 Kb

Official URL: http://dx.doi.org/10.1007/978-3-642-30633-4_13

Exported to Metis

Abstract

Flow-based intrusion detection will play an important role in high-speed networks, due to the stringent performance requirements of packet-based solutions. Flow monitoring technologies, such as NetFlow or IPFIX, aggregate individual packets into flows, requiring new intrusion detection algorithms to deal with the aggregated data. These algorithms are subject to constraints on real-time and accurate detection of intrusions, due to the nature of current flow monitoring technologies. In this paper, we propose a framework for flow-based intrusion detection, aiming to detect intrusions in real-time, and to be resilient against negative effects of attacks on monitoring systems. This research is still in its initial phase and will contribute to a Ph.D. thesis after four years.

Item Type:Conference or Workshop Paper (Full Paper, Talk)
Research Group:EWI-DACS: Design and Analysis of Communication Systems
Research Program:CTIT-DSN: Dependable Systems and Networks
Research Project:UNIVERSELF: Universal Self-management, Next Generation Monitoring Gigaport 3
ID Code:21998
Status:Published
Deposited On:05 July 2012
Refereed:Yes
International:Yes
More Information:statisticsmetis

Export this item as:

To correct this item please ask your editor

Repository Staff Only: edit this item