Efficient Network Monitoring for Attack Detection.
Tobias Limmer · OPUS FAU (Kooperativer Bibliotheksverbund Berlin-Brandenburg (KOBV), on behalf of the Universitätsbibliothek Erlangen-Nürnberg) · 2011
Techniques for network-based intrusion detection have been evolving for years, and the focus of most research is on detection algorithms, although networks are distributed and dynamically managed nowadays. A data processing framework is required that allows to embed multiple detection techniques and to provide data with the needed aggregation levels. Within that framework, this work concentrates on methods that improve the interoperability of intrusion detection techniques and focuses on data preprocessing stages that perform data evaluation and intelligent data filtering. After presenting a survey of the chain of processes needed for network-based intrusion detection, I discuss the evaluation of TCP connection states based on aggregated flow data. I develop classifiers that interpret flow data in regard of failed and successful connections. These classifiers are especially relevant for anomaly-based intrusion detection techniques like port scan or malware detection, and enable many of these techniques to operate on flow-level data instead of packet-level data. The second part focuses on the filtering of payload data for IDSs that use signatures for detection. I perform a detailed analysis of the IDS Snort that locates specific patterns within connections. This analysis led to the first approach, FPA (Front Payload Aggregation), which captures data that is transferred at the beginning of connections. Unfortunately, interleaved communication patterns cannot be captured well using this aggregation technique. Therefore I propose DPA (Dialog-based Payload Aggregation) in the next part, which divides bidirectional communication into dialog segments. For each direction change in the communication, a certain amount of transferred data is kept, and the rest is dropped. This way, bulk data is dropped using a very lightweight method that only relies on network and transport header information. The filter achieved very good results in combination with the IDS Snort, as 89% of the original events could be retained, whereas only 4% of the original amount of data was analyzed by the IDS. To exploit the multi-core architecture of today's CPUs, IDSs are executed in parallel and a load balancer distributes data to the systems. As payload-based analysis is not able to cope with current network speeds even with parallelization, I develop an approach to perform intelligent selection of the captured network data and to distribute selected data to multiple IDSs. The selection algorithm is based on a priority system that keeps track of each host's monitored time and the system controls data losses by monitoring the load of every IDS. My evaluation revealed that the system showed up to 40% better detection results compared to an overloaded system that dropped the same amount of packets in an uncontrolled way due to overload.