IFTS: Intrusion Forecast and Traceback based on Union Defense Environment

Fang−Yie Leu, Weijie Yang, Wen‐Kui Chang · 2005

Network-based intrusion detection system (NIDS) is developed to monitor network traffic in order to detect network intrusion. But it often lacks global cooperative capability. When facing attacks, e.g., DDoS, an intrusion detection system (IDS) needs an overall scheme to respond properly. Also, Internet consists of network management units (NMUs). It would be better if several nearby surrounding NMUs can collaboratively guard and protect their important surrounded neighbor. In this article, we propose an intrusion forecast and traceback system (IFTS) based on union defense environment. IFTS monitors network forwarding traffic, thus forecasting malicious behaviors for its neighbor NMD, called protected NMU (P-NMU). With forecasting, P-NMU can predetermine the way to treat the intrusion packets. IFTS deploys a hash-based intrusion traceback subsystem to trace intruders.

Read the paper · More papers on PaperTik