Detecting attacks in high-speed networks: Issues and solutions. Issue 2 (3rd March 2020)
- Record Type:
- Journal Article
- Title:
- Detecting attacks in high-speed networks: Issues and solutions. Issue 2 (3rd March 2020)
- Main Title:
- Detecting attacks in high-speed networks: Issues and solutions
- Authors:
- Gupta, Alka
Sharma, Lalit Sen - Abstract:
- ABSTRACT: Intrusion detection systems are one of the necessities of networks to identify the problem of network attacks. Organizations striving to protect their data from intruders are often challenged by attackers, who find new ways to attack and compromise the security of the network. The detection process becomes quite difficult while dealing with high-speed and distributed attacks that are performed using botnets. These attacks threat both the confidentiality of legitimate users and the infrastructure of the network and to protect them, early discovery of network attacks is important. In this paper, an open source Intrusion Detection System (IDS), Snort is presented as a solution to detect DoS and Port Scan network attacks in a high-speed network. A set of custom rules has been proposed for Snort to detect DoS and Port Scan attacks in high-speed network. The rules are compared and tested using different attack generators like Scapy, Hping3, LOIC and Nmap . Snort's efficiency in detecting the DoS and Port Scan attacks using the new rules is experimentally proved to be around 99% for all the attacks except for Ping of Death . The proposed system works well for different attack generators in a high-speed network.
- Is Part Of:
- Information security journal. Volume 29:Issue 2(2020)
- Journal:
- Information security journal
- Issue:
- Volume 29:Issue 2(2020)
- Issue Display:
- Volume 29, Issue 2 (2020)
- Year:
- 2020
- Volume:
- 29
- Issue:
- 2
- Issue Sort Value:
- 2020-0029-0002-0000
- Page Start:
- 51
- Page End:
- 61
- Publication Date:
- 2020-03-03
- Subjects:
- NIDS -- NIDPS -- Snort -- D-ITG -- Scapy -- Hping3 -- Nmap -- DoS attacks -- flooding -- Port Scan
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.tandfonline.com/toc/uiss20/current ↗
http://www.tandf.co.uk/journals/titles/19393555.asp ↗
http://www.tandfonline.com/ ↗ - DOI:
- 10.1080/19393555.2020.1722296 ↗
- Languages:
- English
- ISSNs:
- 1939-3555
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4494.315500
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 12791.xml