Welcome to Journal of University of Chinese Academy of Sciences,Today is

›› 2006, Vol. 23 ›› Issue (4): 534-542.DOI: 10.7523/j.issn.2095-6134.2006.4.016

• 论文 • Previous Articles     Next Articles

An Analyse of Packet Sampling Strategy of Network-based Intrusion Detection System

WANG Wei-Ping, ZHU Wei-Wei, CHEN Wen-Hui, LIANG Liang   

  1. School of Management, University of Science & Technology of China, Hefei 230052 China
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-07-15

Abstract: Intrusion detection is an important part of the information security research, and the network-based intrusion detection system accomplish the detection by examine the network packets. Since sampling entails incurring network costs for real-time packet sampling and packet examination hardware, we would like to develop a network packet sampling strategy to effectively detect network intrusions while not exceeding the velocity of the packet examination. We consider this problem in a game theoretic framework and introduce sampling schemes that are optimal in this game theoretic setting by the Minimax theorem and the max-flow min-cut theorem. According to the limitation and scarcity of this single intrusion node method, We introduce a method of risk management and extend the solution to more complex cases to solve the choice of sampling strategy while facing more various environments. At last, we provide an empirical study to exemplify our improved method.

Key words: Intrusion detection, sampling strategy, game theoretic approach, risk management.

CLC Number: