Host Based Detection Approach using Time Based Module for Fast Attack Detection Behavior

Abstract-Intrusion Detection System (IDS) is an important component in a network security infrastructure. IDS need to be accurate and reliable in order to detect the intrusive behaviour of a packet that travelling through the network. With the current technological advancement attack on network inf...

Full description

Saved in:
Bibliographic Details
Main Authors: Abdollah, M. F., Mas’ud, M. Z., Sahib, S., Yaacub, A. H., Yusof, R., Selamat, S. R.
Format: Conference or Workshop Item
Language:English
Published: 2011
Subjects:
Online Access:http://eprints.utem.edu.my/id/eprint/122/1/354.pdf
http://eprints.utem.edu.my/id/eprint/122/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Abstract-Intrusion Detection System (IDS) is an important component in a network security infrastructure. IDS need to be accurate and reliable in order to detect the intrusive behaviour of a packet that travelling through the network. With the current technological advancement attack on network infrastructure has evolve to a new level and to make IDS sensitive enough to detect the new attack, the detection framework need to be frequently updated. Both the fast attack and slow attack mechanism has become the subset of phases inside the anatomy of attack. Each of the attack mechanism has their own criteria and fast attack is the important type of attack that need to be considered as any late detection of the fast attack can cause a major bad impact to the organization. Therefore, there is a need to identify a suitable technique to detect the fast attack and based on this, this paper introduce a static threshold using statistical and observation technique for detecting the fast attack intrusion that is within one second time interval. The Threshold selected was based on the real network traffic dataset and verified using classification table on a real network traffic.