An Approach to Meta-Alert Generation for Anomalous TCP Traffic.

Deeksha Kushwah, Rajni Ranjan Singh, Deepak Singh Tomar · 2018

This is the era of digitization. Almost every service is online these days. As per an estimate till 2020, there will be 730 million internet users, 175 million online shoppers, 70% E-commerce transaction will be via mobile, and 50% travel transactions will be online in India [1]. Along with the growth of online services, the percentage of online crime is also increasing. Online services utilize internet protocols for functioning. TCP is the most commonly used transport layer protocol over the web. Many attackers utilize anomalous TCP flags to scan a system. Therefore it is crucial to research and adopt ways to detect and prevent the TCP packets which contains anomalous TCP flags. Intrusion Detection System is a hardware/software system which is used to detect and prevent attacks. However, it may generate many/false alerts. It is a time-consuming process to manually examine these huge numbers of alerts. Hence, it would be beneficial to generate meta-alerts for similar alerts. In this research work, an approach has been proposed to detect, log and generate meta-alerts for the packets, which contain anomalous TCP flags. To analyze the performance and usefulness of the proposed method an experiment has been carried out using real network traffic, and four well-known datasets i.e. MIT/LL 1998, MIT/LL 1999, Honeynet, and MACCDC dataset. It is observed that overall 99.96% alerts have been reduced. A comparative analysis has been carried out between the proposed work and existing work and it is observed that the proposed method gives better result.

Read the paper · More papers on PaperTik