WG Requirements for network monitoring from an IDS perspective
Lothar Braun · 2008
Detection of malicious traffic is based on its input data, the information that is coming from network-based monitoring systems. Best detection rates would only be possible by monitoring all data transferred over all network lines in a distributed network. Monitoring and reporting this amount of data are feasible in neither today's, nor will be in future's systems. Later analysis like stateful inspection of the traffic imposes even more processing costs. But only at this level of monitoring and analysis there may be a chance to capture all attacks inside a system. So there needs to be a trade-off between detection success and the processing costs. Malicious traffic is mostly generated by compromised systems. Catching attackers during the process of taking over a vulnerable host is complicated, as such attacks only use very low traffic volumes. Operating system security improved in the last years, as because of stack protection and firewalls security holes are more difficult to exploit. To counter this problem, more attacks will base on social engineering techniques like phishing or spam mails. Methods need to be developed to detect those kinds of attacks.