Constrained Row-Based Bit-Parallel Search in Intrusion Detection
Ambika Shrestha Chitrakar, Slobodan V. Petrović · 2016
Most Intrusion Detection Systems (IDS) employ exact search for attack patterns in the analyzed traffic. Because of that, if an attacker introduces changes in the known attack pattern, the obtained new attack pattern becomes impossible to detect. To cope with this problem, an IDS can use approximate search instead of exact search. But then, false positives and false negatives can appear due to the fact that the type and/or the distribution of changes to the old attack traffic pattern is not taken into account. In this paper, we propose a new approximate search algorithm for IDS that introduces constraints on the numbers of individual change operations on the old attack traffic patterns. In such a way, we take into account a-priori knowledge about the type and/or distribution of changes. The experiments show that the false positive and false negative rates obtained with an IDS using approximate search with constraints are significantly reduced compared to a system without constraints. At the same time, the computational cost of introducing constraints is relatively small.