1. Modeling Protocol Based Packet Header Anomaly Detector for Network and Host Intrusion Detection Systems
- Author
-
Michael E. Woodward and Solahuddin B. Shamsuddin
- Subjects
Computer science ,Network packet ,business.industry ,ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS ,Intrusion detection system ,Network layer ,Computer Science::Performance ,Internet Control Message Protocol ,Host-based intrusion detection system ,Stateful firewall ,Header ,Computer Science::Networking and Internet Architecture ,business ,Processing delay ,Computer Science::Cryptography and Security ,Computer network - Abstract
This paper describes an experimental protocol based packet header anomaly detector for Network and Host Intrusion Detection System modelling which analyses the behaviour of packet header field values based on its layer 2, 3 and 4 protocol fields of the ISO OSI Seven Layer Model for Networking. Our model which we call as Protocol based Packet Header Anomaly Detector (PbPHAD) Intrusion Detection System is designed to detect the anomalous behaviour of network traffic packets based on three specific network and transport layer protocols namely UDP, TCP and ICMP to identify the degree of maliciousness from a set of detected anomalous packets identified from the sum of statistically modelled individually rated anomalous field values.
- Published
- 2007