Enhancing Network Intrusion Detection Through Dynamic IP Blacklisting

Zhiyan Lu, Hao Yang, Hao Wu, Yanli Niu · 2024

NIDS play a pivotal role in the modern digital landscape, assisting organizations and enterprises in safeguarding their networks and data from an array of threats. Nevertheless, the escalating network traffic presents a formidable challenge to NIDS, potentially resulting in the loss of regular traffic or a degradation in NIDS performance. This paper introduces a network intrusion detection technology based on a dynamic IP blacklist, offering a solution to this challenge. This innovative approach incorporates an IP blacklist filtering module. By establishing and maintaining an IP blacklist that includes records of known threats, Internet Protocol Addresses, and their corresponding threat levels, NIDS can swiftly pre-filter traffic before it enters the system. This proactive approach allows for the rapid interception of malicious Internet Protocol Addresses and alleviates the computational burden of subsequent in-depth traffic analysis.

Read the paper · More papers on PaperTik