Repository logo
Collections
Browse
Statistics
  • English
  • हिंदी
Log In
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. Theses and Dissertations
  3. M Tech Dissertations
  4. Design and implementation of network intrusion detection system

Design and implementation of network intrusion detection system

Files

200211026.pdf (261.08 KB)

Date

2004

Authors

Jindal, Gaurav

Journal Title

Journal ISSN

Volume Title

Publisher

Dhirubhai Ambani Institute of Information and Communication Technology

Abstract

Most of the intrusion detection systems are based on matching signatures or rules. These rules are the patterns that define the possibility of occurrence of attack. Such signature based intrusion detection system look at incoming events and match these events against the signature rules to detect known attacks. We propose a generic model of Network Intrusion Detection System (NIDS) that includes a signature definition language, signature based detection engine and alert generation and prevention schemes.

This generic model is based on signature classification techniques employed by current signature based NIDS architectures in which signatures are stored in main memory in the form of non-optimized tree or multi link list structures.

At high-speed, techniques employed by signature-based systems become inefficient resulting in performance degradation of NIDS. We have applied clustering and classification algorithm based on decision tree for efficient signature matching. The decision tree classifier approach creates tree from the signature features and its discrete set of values. Decision tree classify the signatures based on features such that each of the signature could be classified either as individual or group identity. We have compared the performance of signature detection engine based on linear as well as decision tree classification. In particular we have shown that tree based classifier outperforms the link list structure by a factor of 4 to 5 when tested by reading sample data from tcp dump files and also the tree classifier has more % of throughput at high data traffic. The % detection varied from 72 % to 30% for tree approach while for linear model % detection varied from 52 % to 30% when packets were flooded at the rate of 4000 to 16000 packets/sec that clearly indicates that linear classifiers dropped more number of packets.

For multi packet inspection we compared sequential based threshold method, adaptive threshold method and cusum algorithms and found that adaptive threshold method and cusum method performs better than sequential time based method in terms of producing less number of false alarms.

Description

Keywords

Communication network architecture, Electronic interference, Internet security, Network intrusion detection system

Citation

Jindal, Gaurav (2004). Design and implementation of network intrusion detection system. Dhirubhai Ambani Institute of Information and Communication Technology, vii, 68 p. (Acc.No: T00018)

URI

http://ir.daiict.ac.in/handle/123456789/55

Collections

M Tech Dissertations

Endorsement

Review

Supplemented By

Referenced By

Full item page
 
Quick Links
  • Home
  • Search
  • Research Overview
  • About
Contact

DAU, Gandhinagar, India

library@dau.ac.in

+91 0796-8261-578

Follow Us

© 2025 Dhirubhai Ambani University
Designed by Library Team