Packet Forensic Analysis in Intrusion Detection Systems

Ednard T. Toivo, Alicia W. Kambrude, Attlee Munyaradzi Gamundani · 2021

The Intrusion Detection System (IDS) is implemented as a security measure to filter suspicious packets that may enter a network. The purpose of the IDS is to alert or as the name suggests ‘detect’ unusual packets that may be considered harmful. The purpose of this research was to understand what information is contained in packets, and how an IDS and additional network management tools work to find malicious data within a packet. This work will form the basis for allowing for a more detailed approach, for when thorough analysis is to be done on the same subject of intrusion detection. IDS packet analysis challenges will be addressed, and possible solutions will be provided. A detailed demonstration on how an IDS uses packets to filter malicious data from acceptable data was done before reaching the conclusion for this work.

Read the paper · More papers on PaperTik