The Experts below are selected from a list of 84 Experts worldwide ranked by ideXlab platform
Abhilash Sonker - One of the best experts on this subject based on the ideXlab platform.
-
Rule-Based Network Intrusion Detection System for Port Scanning with Efficient Port Scan Detection Rules Using Snort
International Journal of Future Generation Communication and Networking, 2016Co-Authors: Satyendra Kumar Patel, Abhilash SonkerAbstract:In the field of network security, researchers have implemented different models to secure the network. Intrusion Detection System is also one of them and Snort is an open source tool for Intrusion Detection and Prevention System. Today intrusion Detection System is a growing technology in network security and mostly researchers have focused in this field, some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In this paper we propose a rule-base Intrusion Detection System with our self generated new Efficient Port Scan Detection Rules (EPSDR). These rules will be used to detect naive port scan attacks in real time network using Snort and Basic Analysis Security Engine (BASE). BASE is used to view the snort results in font-end web page because Snort has no graphic user interface. In This rule-based Intrusion Detection System we will match the signature with our Efficient Port Scan Detection Rules (EPSDR) from Captured Packet. As a definition of signature based IDS this new EPSDR based IDS will be useful to reduce the false positive alarm.
Matjaz Fras - One of the best experts on this subject based on the ideXlab platform.
-
Modeling of statistical data sources based on measured network traffic
SIMULATION, 2012Co-Authors: Matjaz Fras, J. Mohorko, Žarko ČučejAbstract:In the process of network traffic modeling, for simulation purposes, there is often a need for statistical description of traffic data sources. Usually, the network traffic is measured by capturing Packets at a physical level. Normally, the estimation of statistical description of traffic data sources cannot be derived directly from such Captured Packets traffic. For that reason, we have researched for simpler solutions, which are based on the estimation of statistical processes of traffic data sources from the measured Packet network traffic. We have developed the estimation methods, which allow the estimation of suitable probability distribution functions and their parameters of stochastic processes of traffic data sources. Statistical distributions of network traffic processes, such as data lengths process and data inter-arrival time, are important since they can be used for modeling of network traffic in simulation tools. For that reason, the estimation method is firstly developed, which mimics the defragmentation process. This method allows an estimation of distributions of data source network traffic processes and their parameters for Captured Packet traffic. During further testing, this method shows some limitations, especially for the process of data lengths. For that reason, we have developed a new estimation method with the approach described in this paper in further detail. In the new estimation method, which is called estimation method based on histogram comparison (EMHC), we use the opposite concept where distribution of data lengths is transformed by a developed analytical model to a Packet size's histogram. The latter is further compared to a Packet size histogram of Captured Packet traffic. The optimization method is used to find such distribution parameters of the data length process that cause minimal discrepancies between the histogram of Captured Packets and the estimated Packet size histogram. To estimate the discrepancy between two histograms, a well-known I2 test is used, which is modified by a weighting function that considers, beside Packet frequencies, the Packet lengths as well. The proposed algorithm and method are confirmed through validations and experiments in a simulation tool.
-
Data source statistics modeling based on measured Packet traffic: A case study of protocol algorithm and analytical transformation approach
2009 9th International Conference on Telecommunication in Modern Satellite Cable and Broadcasting Services, 2009Co-Authors: Z. Cucej, Matjaz FrasAbstract:For determination of data sources statistics based on measured Packet network traffic many methods and special — consequently expensive — instruments exist. In the searching for alternative, cheaper and simpler solutions, we studied two methods based on Packet network traffic measurement by simple sniffers and transforation of Captured Packet traffic into data sources statistics. We studied two types of algorithms. First group is based on mimic of defragmentation procedure, where algorithms are similar to well known defragmentation protocols. The second group is based on mimic of fragmentation procedure, where we developed new algorithms for identification of probability density function of data sources and new methods for estimation of their parameters. Since we discovered that the estimation heavily depends on measurement of statistical deviations between theoretical and empirical Packet size histograms, we have modified χ2 test by weight function, which considers the Packet length on deviation measure. With this we have achieved better convergency of the developed algorithm. In research we have considered TCP/IP protocol stack and fragmentation/ defragmentation procedures according to RFC 793. Theoretical results are confirmed by numerus experimental tests. The main research and development results are summarized and analyzed.
Arif Khan - One of the best experts on this subject based on the ideXlab platform.
-
Intrusion Detection System (A Layered Based Approach for Finding Attacks)
2013Co-Authors: Kiran Dhangar, Deepak Kulhare, Arif KhanAbstract:This paper titled "Intrusion Detection System A Layered Based Approach for Finding Attacks" is an OSI layered based network intrusion detection system (IDS) proposed. Here we are concentrating and analyzing OSI layers based attack finding technique. Moreover the proposed IDS approve the effectiveness of the proposed system, and presented results shows advantages of host based as well as network based security. The proposed model of IDSs offers several advantages over alternative systems. First of all it provided layers wise (Application, transport and Network) attack find capability that mean all the attack will be capture according to their layers in network based module, it supported high availability and scalability, and most important thing it produced good results in terms of normal and abnormal behaviors of Captured Packet. The proposed model includes integration of individual components to produced batter results. In addition it provide host based intrusion detection functionality, in which two type of attribute find in security event log file one is login-logoff time and another is unauthorized accessing of the host.
-
A Proposed Intrusion Detection System
2013Co-Authors: Kiran Dhangar, Deepak Kulhare, Arif KhanAbstract:This paper titled “Proposed Intrusion Detection System” is an intrusion detection system (IDS) proposed by analyzing the principle of the intrusion detection system based on host and network. Here we are concentrating and analyzing overall performance as well as security of the proposed IDS. Moreover the proposed IDS approve the effectiveness of the proposed method, and presented results shows advantages of host based as well as network based security. The proposed model of hybrid IDSs offers several advantages over alternative systems. First of all it provided higher security, it supported high availability and scalability, and most important thing it produced good results in terms of normal and abnormal behaviors of Captured Packet. The proposed model includes integration of individual components to produced batter results.
Sunil B Wankhede - One of the best experts on this subject based on the ideXlab platform.
-
Network Intrusion Detection System
International Journal of Advance Research and Innovative Ideas in Education, 2017Co-Authors: Kunal Iyengar, Grishma Wadhia, Parth Vasani, Jyoti Mishra, Sunil B WankhedeAbstract:Intrusion detection has become a critical component of network administration due to the vast number of attacks persistently threaten our computers. Traditional intrusion detection systems are limited and do not provide a complete solution for the problem. Here we are concentrating and analyzing overall performance as well as security of the proposed IDS. Moreover the proposed IDS approve the effectiveness of the proposed method, and presented results shows advantages of network based security. The proposed model of IDSs offers several advantages over alternative systems. First of all it provided higher security, it supported high availability and scalability, and most important thing it produced good results in terms of normal and abnormal behaviors of Captured Packet. The proposed model includes integration of individual components to produced batter results. Packet sniffing or Packet capture software is extensively used as tools for protocol analysis and security. In protocol design research, such a tool comes handy in analyzing, debugging and testing of a new protocol implementation. In Security, as is true for any tools, it may be used both as a positive way to detect intrusions or attacks on a system as well as in the malicious way to hack for private and personal data of others. Even though use of upper layer encryption techniques make it difficult to gather data directly, yet these tools are important in learning about existing sessions, collecting encrypted data to launch offline attacks to generate the encryption key and any such attack limited only by ones imagination. Packet sniffing is integrated with our project as a key tool to extract the headers of Packets to differentiate them from rest of the malicious content.
Satyendra Kumar Patel - One of the best experts on this subject based on the ideXlab platform.
-
Rule-Based Network Intrusion Detection System for Port Scanning with Efficient Port Scan Detection Rules Using Snort
International Journal of Future Generation Communication and Networking, 2016Co-Authors: Satyendra Kumar Patel, Abhilash SonkerAbstract:In the field of network security, researchers have implemented different models to secure the network. Intrusion Detection System is also one of them and Snort is an open source tool for Intrusion Detection and Prevention System. Today intrusion Detection System is a growing technology in network security and mostly researchers have focused in this field, some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In this paper we propose a rule-base Intrusion Detection System with our self generated new Efficient Port Scan Detection Rules (EPSDR). These rules will be used to detect naive port scan attacks in real time network using Snort and Basic Analysis Security Engine (BASE). BASE is used to view the snort results in font-end web page because Snort has no graphic user interface. In This rule-based Intrusion Detection System we will match the signature with our Efficient Port Scan Detection Rules (EPSDR) from Captured Packet. As a definition of signature based IDS this new EPSDR based IDS will be useful to reduce the false positive alarm.