Welcome to Journal of University of Chinese Academy of Sciences,Today is
论文

An Analyse of Packet Sampling Strategy of Network-based Intrusion Detection System

  • WANG Wei-Ping ,
  • ZHU Wei-Wei ,
  • CHEN Wen-Hui ,
  • LIANG Liang
Expand
  • School of Management, University of Science & Technology of China, Hefei 230052 China

Received date: 1900-01-01

  Revised date: 1900-01-01

  Online published: 2006-07-15

Abstract

Intrusion detection is an important part of the information security research, and the network-based intrusion detection system accomplish the detection by examine the network packets. Since sampling entails incurring network costs for real-time packet sampling and packet examination hardware, we would like to develop a network packet sampling strategy to effectively detect network intrusions while not exceeding the velocity of the packet examination. We consider this problem in a game theoretic framework and introduce sampling schemes that are optimal in this game theoretic setting by the Minimax theorem and the max-flow min-cut theorem. According to the limitation and scarcity of this single intrusion node method, We introduce a method of risk management and extend the solution to more complex cases to solve the choice of sampling strategy while facing more various environments. At last, we provide an empirical study to exemplify our improved method.

Cite this article

WANG Wei-Ping , ZHU Wei-Wei , CHEN Wen-Hui , LIANG Liang . An Analyse of Packet Sampling Strategy of Network-based Intrusion Detection System[J]. Journal of University of Chinese Academy of Sciences, 2006 , 23(4) : 534 -542 . DOI: 10.7523/j.issn.2095-6134.2006.4.016

Outlines

/