메뉴 건너뛰기




Volumn 39, Issue 1, 2014, Pages 83-92

Adaptive blacklist-based packet filter with a statistic-based approach in network intrusion detection

Author keywords

Adaptive system; Blacklist generation; Network intrusion detection; Packet filter; Signature matching

Indexed keywords

ANOMALY-BASED NIDS; BLACKLIST GENERATION; EVALUATION RESULTS; NETWORK ENVIRONMENTS; NETWORK INTRUSION DETECTION; NETWORK INTRUSION DETECTION SYSTEMS; PACKET FILTERS; SIGNATURE-MATCHING;

EID: 84893779151     PISSN: 10848045     EISSN: 10958592     Source Type: Journal    
DOI: 10.1016/j.jnca.2013.05.009     Document Type: Article
Times cited : (40)

References (45)
  • 1
    • 0016518897 scopus 로고
    • Fast pattern matching an aid to bibliographic search
    • A.V. Aho, and M.J. Corasick Fast pattern matching an aid to bibliographic search Communications of the ACM 18 1975 333 340
    • (1975) Communications of the ACM , vol.18 , pp. 333-340
    • Aho, A.V.1    Corasick, M.J.2
  • 2
    • 77955273948 scopus 로고    scopus 로고
    • Hierarchical packet classification using a bloom filter and rule-priority tries
    • A.G. Alagu Priya, and H. Lim Hierarchical packet classification using a bloom filter and rule-priority tries Computer Communications 33 10 2010 1215 1226
    • (2010) Computer Communications , vol.33 , Issue.10 , pp. 1215-1226
    • Alagu Priya, A.G.1    Lim, H.2
  • 3
    • 33846098197 scopus 로고    scopus 로고
    • Bayesian neural networks for internet traffic classification
    • DOI 10.1109/TNN.2006.883010
    • T. Auld, A.W. Moore, and S.F. Gull Bayesian neural networks for internet traffic classification IEEE Transactions on Neural Networks 18 1 2007 223 239 (Pubitemid 46062929)
    • (2007) IEEE Transactions on Neural Networks , vol.18 , Issue.1 , pp. 223-239
    • Auld, T.1    Moore, A.W.2    Gull, S.F.3
  • 5
    • 84928016636 scopus 로고    scopus 로고
    • The base-rate fallacy and the difficulty of intrusion detection
    • S. Axelsson The base-rate fallacy and the difficulty of intrusion detection ACM Transactions on Information and System Security 3 3 2000 186 205
    • (2000) ACM Transactions on Information and System Security , vol.3 , Issue.3 , pp. 186-205
    • Axelsson, S.1
  • 6
    • 0017547820 scopus 로고
    • A fast string searching algorithm
    • R.S. Boyer, and J.S. Moore A fast string searching algorithm Communications of the ACM 20 10 1977 762 772
    • (1977) Communications of the ACM , vol.20 , Issue.10 , pp. 762-772
    • Boyer, R.S.1    Moore, J.S.2
  • 7
    • 77953309234 scopus 로고    scopus 로고
    • CompactDFA: Generic state machine compression for scalable pattern matching
    • Bremler-Barr, A., Hay, D., Koral, Y., CompactDFA: generic state machine compression for scalable pattern matching. In: Proceedings of the IEEE INFOCOM; 2010. p. 1-9.
    • (2010) Proceedings of the IEEE INFOCOM , pp. 1-9
    • Bremler-Barr, A.1    Hay, D.2    Koral, Y.3
  • 8
    • 84857042908 scopus 로고    scopus 로고
    • On the bit-parallel simulation of the nondeterministic Aho-Corasick and suffix automata for a set of patterns
    • D. Cantone, S. Faro, and E. Giaquinta On the bit-parallel simulation of the nondeterministic Aho-Corasick and suffix automata for a set of patterns Journal of Discrete Algorithms 11 1 2012 25 36
    • (2012) Journal of Discrete Algorithms , vol.11 , Issue.1 , pp. 25-36
    • Cantone, D.1    Faro, S.2    Giaquinta, E.3
  • 9
    • 79961024286 scopus 로고    scopus 로고
    • A fast pattern matching algorithm with multi-byte search unit for high-speed network security
    • Y.-H. Choi, M.-Y. Jung, and S.-W. Seo A fast pattern matching algorithm with multi-byte search unit for high-speed network security Computer Communications 34 14 2011 1750 1763
    • (2011) Computer Communications , vol.34 , Issue.14 , pp. 1750-1763
    • Choi, Y.-H.1    Jung, M.-Y.2    Seo, S.-W.3
  • 11
    • 58049158700 scopus 로고    scopus 로고
    • 〈 âŒ.
    • DARPA Intrusion Detection Evaluation Data Set, 1999. 〈 http://www.ll.mit.edu/mission/communications/ist/corpora/ideval/data/1999data. html âŒ.
    • (1999) DARPA Intrusion Detection Evaluation Data Set
  • 15
    • 57349145365 scopus 로고    scopus 로고
    • Wire-speed TCAM-based architectures for multimatch packet classification
    • M. Faezipour, and M. Nourani Wire-speed TCAM-based architectures for multimatch packet classification IEEE Transactions on Computers 58 1 2009 5 17
    • (2009) IEEE Transactions on Computers , vol.58 , Issue.1 , pp. 5-17
    • Faezipour, M.1    Nourani, M.2
  • 16
    • 2442461381 scopus 로고    scopus 로고
    • An analysis of fast string matching applied to content-based forwarding and intrusion detection
    • University of California, San Diego
    • Fisk M, Varghese G. An analysis of fast string matching applied to content-based forwarding and intrusion detection. Technical Report CS2001-0670, University of California, San Diego; 2002.
    • (2002) Technical Report CS2001-0670
    • Fisk, M.1    Varghese, G.2
  • 18
    • 70349661805 scopus 로고    scopus 로고
    • Variable-stride multi-pattern matching for scalable deep packet inspection
    • Hua N, Song H, Lakshman TV. Variable-stride multi-pattern matching for scalable deep packet inspection. In: Proceedings of the IEEE INFOCOM; 2009. p. 415-23.
    • (2009) Proceedings of the IEEE INFOCOM , pp. 415-423
    • Hua, N.1    Song, H.2    Lakshman, T.V.3
  • 21
    • 80053570343 scopus 로고    scopus 로고
    • A memory-efficient bit-split parallel string matching using pattern dividing for intrusion detection systems
    • H.-J. Kim, H.-S. Kim, and S. Kang A memory-efficient bit-split parallel string matching using pattern dividing for intrusion detection systems IEEE Transactions on Parallel and Distributed Systems 22 11 2011 1904 1911
    • (2011) IEEE Transactions on Parallel and Distributed Systems , vol.22 , Issue.11 , pp. 1904-1911
    • Kim, H.-J.1    Kim, H.-S.2    Kang, S.3
  • 22
    • 84864724103 scopus 로고    scopus 로고
    • A new hierarchical packet classification algorithm
    • H. Lim, S. Lee Jr., and E.E. Swartzlander A new hierarchical packet classification algorithm Computer Networks 56 13 2012 3010 3022
    • (2012) Computer Networks , vol.56 , Issue.13 , pp. 3010-3022
    • Lim, H.1    Lee, Jr.S.2    Swartzlander, E.E.3
  • 23
    • 84855746345 scopus 로고    scopus 로고
    • 〈 âŒ.
    • Mcafee Threat Report: Second Quarter 2012. 〈 http://www.mcafee.com/us/resources/reports/rp-quarterly-threat-q2-2012.pdf âŒ.
    • (2012) Mcafee Threat Report: Second Quarter
  • 24
    • 85019691440 scopus 로고    scopus 로고
    • Testing intrusion detection systems: A critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by lincoln laboratory
    • McHugh J. Testing intrusion detection systems: a critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by lincoln laboratory. ACM Transactions on Information System Security 2000: 262-94.
    • (2000) ACM Transactions on Information System Security , pp. 262-294
    • McHugh, J.1
  • 26
    • 84864693379 scopus 로고    scopus 로고
    • A prefix-based approach for managing hybrid specifications in complex packet filtering
    • N.B. Neji, and A. Bouhoula A prefix-based approach for managing hybrid specifications in complex packet filtering Computer Networks 56 13 2012 3055 3064
    • (2012) Computer Networks , vol.56 , Issue.13 , pp. 3055-3064
    • Neji, N.B.1    Bouhoula, A.2
  • 28
    • 84867325287 scopus 로고    scopus 로고
    • Multi-stride string searching for high-speed content inspection
    • D. Pao, and X. Wang Multi-stride string searching for high-speed content inspection The Computer Journal 55 10 2012 1216 1231
    • (2012) The Computer Journal , vol.55 , Issue.10 , pp. 1216-1231
    • Pao, D.1    Wang, X.2
  • 29
    • 0033295259 scopus 로고    scopus 로고
    • Bro: A system for detecting network intruders in real-time
    • V. Paxson Bro: a system for detecting network intruders in real-time Computer Networks 31 23-24 1999 2435 2463
    • (1999) Computer Networks , vol.31 , Issue.2324 , pp. 2435-2463
    • Paxson, V.1
  • 31
    • 0007526771 scopus 로고
    • On the worst-case behavior of string-searching algorithms
    • R.L. Rivest On the worst-case behavior of string-searching algorithms SIAM Journal on Computing 1977 669 674
    • (1977) SIAM Journal on Computing , pp. 669-674
    • Rivest, R.L.1
  • 32
    • 85090433665 scopus 로고    scopus 로고
    • Snort: Lightweight intrusion detection for networks
    • Roesch M. Snort: lightweight intrusion detection for networks. In: Proceedings of the usenix lisa conference; 1999, p. 229-38.
    • (1999) Proceedings of the Usenix Lisa Conference , pp. 229-238
    • Roesch, M.1
  • 33
    • 58149104386 scopus 로고    scopus 로고
    • Guide to intrusion detection and prevention systems (IDPS)
    • February
    • Scarfone K, Mell P. Guide to intrusion detection and prevention systems (IDPS). NIST Special Publication 800-94; February 2007.
    • (2007) NIST Special Publication 800-94
    • Scarfone, K.1    Mell, P.2
  • 37
    • 20344366573 scopus 로고    scopus 로고
    • Efficient packet classification for network intrusion detection using FPGA
    • ACM/SIGDA Thirteenth ACM International Symposium on Field Programmable Gate Arrays - FPGA 2005
    • Song H, Lockwood JW. Efficient packet classification for network intrusion detection using fpga. In: Proceedings of the ACM/SIGDA international symposium on field programmable gate arrays; February 2005. p. 238-45. (Pubitemid 40787613)
    • (2005) ACM/SIGDA International Symposium on Field Programmable Gate Arrays - FPGA , pp. 238-245
    • Song, H.1    Lockwood, J.W.2
  • 38
    • 79953216012 scopus 로고    scopus 로고
    • Toward advocacy-free evaluation of packet classification algorithms
    • H. Song, and J.S. Turner Toward advocacy-free evaluation of packet classification algorithms IEEE Transactions on Computers 60 5 2011 723 733
    • (2011) IEEE Transactions on Computers , vol.60 , Issue.5 , pp. 723-733
    • Song, H.1    Turner, J.S.2
  • 40
    • 79551525456 scopus 로고    scopus 로고
    • MS-DFA multiple-stride pattern matching for scalable deep packet inspection
    • L. Vespa, N. Weng, and R. Ramaswamy MS-DFA multiple-stride pattern matching for scalable deep packet inspection The Computer Journal 54 2 2011 285 303
    • (2011) The Computer Journal , vol.54 , Issue.2 , pp. 285-303
    • Vespa, L.1    Weng, N.2    Ramaswamy, R.3
  • 41
    • 61749094228 scopus 로고    scopus 로고
    • Scalable packet classification with controlled cross-producting
    • P.C. Wang Scalable packet classification with controlled cross-producting Computer Networks 53 6 2009 821 834
    • (2009) Computer Networks , vol.53 , Issue.6 , pp. 821-834
    • Wang, P.C.1
  • 45
    • 0012405865 scopus 로고
    • A fast algorithm for multi-pattern searching
    • Department of Computer Science, University of Arizona; May
    • Wu S, Manber U. A fast algorithm for multi-pattern searching. Technical Report TR-94-17, Department of Computer Science, University of Arizona; May 1994.
    • (1994) Technical Report TR-94-17
    • Wu, S.1    Manber, U.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.