Detail výsledku

Towards Real-Time Intrusion Detection for NetFlow and IPFIX

HOFSTEDE, R.; BARTOŠ, V.; SPEROTTO, A.; PRAS, A. Towards Real-Time Intrusion Detection for NetFlow and IPFIX. In Proceedings of the 9th International Conference on Network and Service Management. Zürich: International Federation for Information Processing, 2013. p. 1-6. ISBN: 978-3-901882-53-1.
Typ
článek ve sborníku konference
Jazyk
anglicky
Autoři
Hofstede Rick
Bartoš Václav, Ing., Ph.D., UPSY (FIT)
Sperotto Anna
Pras Aiko
Abstrakt

DDoS attacks bring serious economic and technical damage to networks and enterprises. Timely detection and mitigation are therefore of great importance. However, when flow monitoring systems are used for intrusion detection, as it is often the case in campus, enterprise and backbone networks, timely data analysis is constrained by the architecture of NetFlow and IPFIX. In their current architecture, the analysis is performed after certain timeouts, which generally delays the intrusion detection for several minutes. This paper presents a functional extension for both NetFlow and IPFIX flow exporters, to allow for timely intrusion detection and mitigation of large flooding attacks. The contribution of this paper is threefold. First, we integrate a lightweight intrusion detection module into a flow exporter, which moves detection closer to the traffic observation point. Second, our approach mitigates attacks in near real-time by instructing firewalls to filter malicious traffic. Third, we filter flow data of malicious traffic to prevent flow collectors from overload. We validate our approach by means of a prototype that has been deployed on a backbone link of the Czech national research and education network CESNET.

Klíčová slova

Internet measurements, Denial of service, Intrusion
detection, NetFlow, IPFIX, Flow monitoring

URL
Rok
2013
Strany
1–6
Sborník
Proceedings of the 9th International Conference on Network and Service Management
Konference
9th International Conference on Network and Service Management
ISBN
978-3-901882-53-1
Vydavatel
International Federation for Information Processing
Místo
Zürich
UT WoS
000345853200039
BibTeX
@inproceedings{BUT104510,
  author="Rick {Hofstede} and Václav {Bartoš} and Anna {Sperotto} and Aiko {Pras}",
  title="Towards Real-Time Intrusion Detection for NetFlow and IPFIX",
  booktitle="Proceedings of the 9th International Conference on Network and Service Management",
  year="2013",
  pages="1--6",
  publisher="International Federation for Information Processing",
  address="Zürich",
  isbn="978-3-901882-53-1",
  url="http://www.cnsm-conf.org/2013/documents/papers/CNSM/p227-hofstede.pdf"
}
Soubory
Projekty
Centrum excelence IT4Innovations, MŠMT, Operační program Výzkum a vývoj pro inovace, ED1.1.00/02.0070, zahájení: 2011-01-01, ukončení: 2015-12-31, ukončen
Pokročilé bezpečné, spolehlivé a adaptivní IT, VUT, Vnitřní projekty VUT, FIT-S-11-1, zahájení: 2011-01-01, ukončení: 2013-12-31, ukončen
Výzkum informačních technologií z hlediska bezpečnosti, MŠMT, Institucionální prostředky SR ČR (např. VZ, VC), MSM0021630528, zahájení: 2007-01-01, ukončení: 2013-12-31, řešení
Výzkumné skupiny
Pracoviště
Nahoru