Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Towards Online Flow-level Anomaly/Intrusion Detection System for High-speed Networks

Traffic anomalies and attacks are commonplace in today's networks, and identifying them rapidly and accurately is critical for large network operators. We propose a High-speed Router-based Anomaly and Intrusion Detection system, HRAID, leveraging the recent work on data streaming computation and in particular, sketches. We analyze the attributes in TCP/IP headers and select an optimal small set of metrics for flow-level sketch-based traffic monitoring and intrusion detection. To overcome the limitations of existing single-dimensional sketches, we design an efficient two-dimensional sketches to further distinguish different type of attacks for mitigation.

We further propose several heuristics to reduce the false positive for SYN flooding detection. Simulation with several router traces shows that HRAID is highly accurate, efficient, uses very small memory, and can effectively detect multiple types of attacks simultaneously. In addition, we compare HRAID with other state-of-the-art detection schemes, and validate the attacks detected.

To the best of our knowledge, HRAID is the first online flow-level anomaly/intrusion detection system for high-speed networks, even for the worst case traffic of 40-byte-packet streams with each packet forming a flow.

Yan Chen

BibTeX
@conference {269228,
author = {Yan Chen},
title = {Towards Online Flow-level {Anomaly/Intrusion} Detection System for High-speed Networks},
year = {2005},
address = {Baltimore, MD},
publisher = {USENIX Association},
month = jul
}
Download

Links

Slides: 
http://usenix.org/events/sec05/wips/chen.pdf
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us