REHÁK, Martin, Michal PĚCHOUČEK, Karel BARTOŠ, Martin GRILL, Pavel ČELEDA a Vojtěch KRMÍČEK. CAMNEP: An intrusion detection system for high-speed networks. Progress in Informatics. 2008, roč. 2008, č. 5, s. 65-74. ISSN 1349-8614. |
Další formáty:
BibTeX
LaTeX
RIS
@article{764212, author = {Rehák, Martin and Pěchouček, Michal and Bartoš, Karel and Grill, Martin and Čeleda, Pavel and Krmíček, Vojtěch}, article_number = {5}, keywords = {intrusion detection network; behavior analysis; multi-agent system; trust; anomaly detection}, language = {eng}, issn = {1349-8614}, journal = {Progress in Informatics}, title = {CAMNEP: An intrusion detection system for high-speed networks}, url = {http://www.nii.ac.jp/pi/}, volume = {2008}, year = {2008} }
TY - JOUR ID - 764212 AU - Rehák, Martin - Pěchouček, Michal - Bartoš, Karel - Grill, Martin - Čeleda, Pavel - Krmíček, Vojtěch PY - 2008 TI - CAMNEP: An intrusion detection system for high-speed networks JF - Progress in Informatics VL - 2008 IS - 5 SP - 65-74 EP - 65-74 SN - 13498614 KW - intrusion detection network KW - behavior analysis KW - multi-agent system KW - trust KW - anomaly detection UR - http://www.nii.ac.jp/pi/ N2 - The presented research aims to detect malicious traffic in high speed networks by means of correlated anomaly detection methods. In order to acquire the real-time traffic statistics in NetFlow format, we deploy transparent inline probes based on FPGA elements. They provide traffic statistics to the agent-based detection layer, where each agent uses a specific anomaly detection method to detect anomalies and describe the flows in its extended trust model. The agents share the anomaly assessments of individual network flows that are used as an input for the agents trust models. The trustfulness values of individual flows from all agents are combined to estimate their maliciousness. The estimate of trust is subsequently used to filter out the most significant events that are reported to network operators for further analysis. We argue that the use of trust model for integration of several anomaly detection methods and efficient representation of history data shall reduce the high rate of false positives (legitimate traffic classified as malicious) which limits the effectiveness of current intrusion detection systems. ER -
REHÁK, Martin, Michal PĚCHOUČEK, Karel BARTOŠ, Martin GRILL, Pavel ČELEDA a Vojtěch KRMÍČEK. CAMNEP: An intrusion detection system for high-speed networks. \textit{Progress in Informatics}. 2008, roč.~2008, č.~5, s.~65-74. ISSN~1349-8614.
|