Analysis of a Payload-based Network Intrusion Detection System Using Pattern Recognition Processors

Irshad M. Iqbal, Ricardo A. Calix · 2016

Intrusion detection systems are a necessary tool to protect computer networks from cyber-attacks. Analyzing the payload of a packet can help in identifying strings that can help to detect attacks. Machine learning can be used to train models based on feature extraction of packet payloads. One important issue is that payload based intrusion detection systems may be too slow for standard processing approaches. Analyzing payloads has advantages over analyzing the standard headers of a packet. However, this approach is more resource intensive. The purpose of this study is to analyze the speed and accuracy performance of a payload based network intrusion detection system using pattern recognition processor with a unigram feature extraction approach. Results of the study are presented and discussed.

Read the paper · More papers on PaperTik