Enhancing the performance of signature-based network intrusion detection systems : An engineering approach
Research output: Journal Publications and Reviews › RGC 22 - Publication in policy or professional journal
Author(s)
Related Research Unit(s)
Detail(s)
Original language | English |
---|---|
Pages (from-to) | 209-222 |
Journal / Publication | HKIE Transactions Hong Kong Institution of Engineers |
Volume | 21 |
Issue number | 4 |
Publication status | Published - 2 Oct 2014 |
Link(s)
Abstract
Signature-based network intrusion detection systems (NIDSs) have been popularly implemented in different organisations, with the purpose of defending against various attacks. However, it is identified that these systems suffer from three major issues in practical applications such as overload packets, expensive signature matching and massive false alarms, which would significantly decrease the effectiveness of these systems. In this paper, an adaptive framework is proposed to improve the overall performance of a signature-based NIDS such as Snort regarding the aforementioned issues. This framework is further implemented in an engineering way, in which a trust-based packet filter with an exclusive signature matching scheme, and an intelligent machine learning-based false alarm filter aiming to reduce target packets, improve the process of signature matching and decrease the number of false alarms are constructed, respectively. In the evaluation, the experimental results on a well-known benchmark and a real network environment demonstrate that this approach and implementation can provide overall improvements for a signature-based NIDS such as Snort in the aspects of packet filtration, signature matching improvement and false alarm reduction.
Research Area(s)
- false alarm reduction, network intrusion detection, network security, packet filtration, signature matching, signature-based approach, Snort
Citation Format(s)
Enhancing the performance of signature-based network intrusion detection systems: An engineering approach. / Meng, Weizhi; Kwok, Lam For.
In: HKIE Transactions Hong Kong Institution of Engineers, Vol. 21, No. 4, 02.10.2014, p. 209-222.
In: HKIE Transactions Hong Kong Institution of Engineers, Vol. 21, No. 4, 02.10.2014, p. 209-222.
Research output: Journal Publications and Reviews › RGC 22 - Publication in policy or professional journal