Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Characterizing and Improving Distributed Intrusion Detection Systems.

Technical Report ·
DOI:https://doi.org/10.2172/1139982· OSTI ID:1139982

Due to ever-increasing quantities of information traversing networks, network administrators are developing greater reliance upon statistically sampled packet information as the source for their intrusion detection systems (IDS). Our research is aimed at understanding IDS performance when statistical packet sampling is used. Using the Snort IDS and a variety of data sets, we compared IDS results when an entire data set is used to the results when a statistically sampled subset of the data set is used. Generally speaking, IDS performance with statistically sampled information was shown to drop considerably even under fairly high sampling rates (such as 1:5). Characterizing and Improving Distributed Intrusion Detection Systems4AcknowledgementsThe authors wish to extend our gratitude to Matt Bishop and Chen-Nee Chuah of UC Davis for their guidance and support on this work. Our thanks are also extended to Jianning Mai of UC Davis and Tao Ye of Sprint Advanced Technology Labs for their generous assistance.We would also like to acknowledge our dataset sources, CRAWDAD and CAIDA, without which this work would not have been possible. Support for OC48 data collection is provided by DARPA, NSF, DHS, Cisco and CAIDA members.

Research Organization:
Sandia National Laboratories (SNL-CA), Livermore, CA (United States)
Sponsoring Organization:
USDOE National Nuclear Security Administration (NNSA)
DOE Contract Number:
AC04-94AL85000
OSTI ID:
1139982
Report Number(s):
SAND2007-7575; 520160
Country of Publication:
United States
Language:
English

Similar Records

Applying Fast String Matching to Intrusion Detection
Conference · Sun Dec 31 23:00:00 EST 2000 · OSTI ID:975767

Alerts Visualization and Clustering in Network-based Intrusion Detection
Conference · Thu Apr 01 00:00:00 EDT 2010 · OSTI ID:986833

Security Evaluation of Two Intrusion Detection Systems in Smart Grid SCADA Environment
Conference · Sat Sep 01 00:00:00 EDT 2018 · 2018 North American Power Symposium (NAPS) · OSTI ID:1985687

Related Subjects