Skip to main navigation Skip to search Skip to main content

Improving the accuracy of network intrusion detection systems under load using selective packet discarding

  • Foundation for Research and Technology-Hellas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

35 Scopus citations

Abstract

Under conditions of heavy traffic load or sudden traffic bursts, the peak processing throughput of network intrusion detection systems (NIDS) may not be sufficient for inspecting all monitored traffic, and the packet capturing subsystem inevitably drops excess arriving packets before delivering them to the NIDS. This impedes the detection ability of the system and leads to missed attacks. In this work we present selective packet discarding, a best effort approach that enables the NIDS to anticipate overload conditions and minimize their impact on attack detection. Instead of letting the packet capturing subsystem randomly drop arriving packets, the NIDS proactively discards packets that are less likely to affect its detection accuracy, and focuses on the traffic at the early stages of each network flow. We present the design of selective packet discarding and its implementation in Snort NIDS. Our experiments show that selective packet discarding significantly improves the detection accuracy of Snort under increased traffic load, allowing it to detect attacks that would have otherwise been missed.

Original languageEnglish
Title of host publicationProceedings of the 3rd European Workshop on System Security, EUROSEC'10
PublisherAssociation for Computing Machinery (ACM)
Pages15-21
Number of pages7
ISBN (Print)9781450300599
DOIs
StatePublished - Apr 13 2010
Event3rd European Workshop on System Security, EUROSEC 2010 - Paris, France
Duration: Apr 13 2010Apr 13 2010

Publication series

NameProceedings of the 3rd European Workshop on System Security, EUROSEC'10

Conference

Conference3rd European Workshop on System Security, EUROSEC 2010
Country/TerritoryFrance
CityParis
Period04/13/1004/13/10

Keywords

  • Intrusion detection
  • Overload control
  • Selective packet discarding

Fingerprint

Dive into the research topics of 'Improving the accuracy of network intrusion detection systems under load using selective packet discarding'. Together they form a unique fingerprint.

Cite this