- Research Article
- 10.25972/opus-22421
Attack-aware Security Function Management
- May 03, 2021
- Online Publication Service of Würzburg University (Würzburg University)
- Lukas Iffländer
Attack-aware Security Function Management
Although Software-defined networking (SDN) is a promising architecture that simplifies network management and control, it also faces security problems that may affect the whole network. Hence, protecting strategies, such as intrusion detection and prevention system (IDPS), are in need in the SDN context. The potential of machine learning-based solutions can become the motivation of cut-edge deep learning-based intrusion detection system that can leverage the centralized control and view of the controller to secure the underlying infrastructure. However, performing additional IDPS functions in the controller, which needs to process enormous traffic amounts, can overload this component, and slow down the network. This paper introduces an approach of Big Data analysis for intrusion detection system in SDN, named BIDSDN to enhance the classification perfor-mance with a massive amount of network traffic data. Specifically, we leverage Apache Spark to deploy the distributed deep learning – based detector to reduce the processing time on complex algorithms. The experiments conducted on CICIDS2018 dataset with distributed cluster prove the efficacy in tackling the Big Data-related issues in the large-scale network like SDN.
Attack-aware Security Function Management
Attack-aware Security Function Management
Technologies, Methodologies and Challenges in Network Intrusion Detection and Prevention Systems
This paper presents an overview of the technologies and the methodologies used in Network Intrusion Detection and Prevention Systems (NIDPS). Intrusion Detection and Prevention System (IDPS) technologies are differentiated by types of events that IDPSs can recognize, by types of devices that IDPSs monitor and by activity. NIDPSs monitor and analyze the streams of network packets in order to detect security incidents. The main methodology used by NIDPSs is protocol analysis. Protocol analysis requires good knowledge of the theory of the main protocols, their definition, how each protocol works.Keywords: Intrusion Detection and Prevention System, Protocol Analysis, Sensor, Signature, State(ProQuest: ... denotes formulae omitted.)1 IntroductionIncreasing size and complexity of the Internet and Intranet networks have led to increasing number of vulnerabilities that could be exploited. Thus, the internal and external attacks on the information systems are increasing at an alarming rate. Also, these are becoming more severe and sophisticated. The attackers find ingenious ways to bypass the security controls and to compromise the security and the well functioning of the information systems. They are motivated by financial, political, and military objectives. In this context, defending wide area networks from malicious traffic, unauthorized access to systems involves many problems.In security information systems Network Intrusion Detection and Prevention Systems (NIDPS) are important tools to detect possible incidents and also, to attempt to stop them in real time. Due to changing attacks, intrusion detection methodologies and technologies continuously evolve, adding new detection capabilities, to avoid detection. They must adapt to new forms of malware, to the public networks, increased traffic.2 Concepts of Intrusion DetectionAn intrusion is a successful action to gain access to an information system, to compromise it or to make it unavailable. This is possible due to the presence of vulnerability in the target system that can be exploited by a motivated intruder.Intrusion Detection and Prevention is the process of monitoring the information systems by sensors or agents and analyzing the collected information to detect and to attempt to stop the attacks in real time, identifying vulnerabilities, the violation of security policies or standard security practices.An Intrusion Detection and Prevention System (IDPS) is a tool that monitors information systems, collects, analyzes information, and initiates responses when an intrusion is detected.Intrusion Detection Systems (IDSs) mainly work as defensive mechanisms. They only alert the system administrators that an incident has occurred. Intrusion Prevention Systems (IPSs) can take some actions to attempt to stop the attack, such as breaking the connection or modifying the firewall rules to deny access to the intruder. The response of the classic IDS can be slow if the system administrator is busy while the response of the IPS is automatic. An architecture that uses together IPS and IDS technologies is the best solution for defense in depth.Conceptually, a generic IDPS consists of modular components. It mainly has the following components: monitoring system, storage, analyzer, and responder.* Monitoring system - monitors and logs the events in a computer system or network;* Storage - stores information, called audit record, about suspicious activities or intrusions; also, the security policies used in analysis are stored;* Analyzer - uses different analysis methodologies to detect the incidents;* Responder - the response mechanism of incidents.The IDPSs could be classified as:* By detection methodology [12], [18]:- misuse-based detection- anomaly-based detection- stateful protocol analysis* By activity [12]:- network-based- wireless-based- network behavior analysis- host-based* By behavior on detection:- passive- active* By collection and analysis frequency:- continuous- periodicThe detection methodologies describe the characteristics of the analyzer. …
Read moreAsIDPS: Auto-Scaling Intrusion Detection and Prevention System for Cloud
Distributed Denial-of-Service (DDoS) attack has been a “nightmare” for cloud. A countermeasure is to establish an Intrusion Detection and Prevention System (IDPS) for cloud. Nevertheless, current IDPSes fail to achieve the detection and prevention in a flexible and lightweight way. In this paper, we propose a novel scheme of IDPS for overcoming the above problem, termed as Auto-scaling IDPS (AsIDPS). AsIDPS is based on Software-Defined Networking (SDN) and Docker container technologies. It first detects abnormal traffic based on the flow statistics collected in SDN switches in real-time. By the SDN controller, the abnormal traffic will be directed to the created Docker containers with Snort running on them for further detection and clean-up. Particularly, the Docker containers can be automatically scaled out or scaled down on demand. The Snort will also deliver an alert to the SDN controller if it detects attack traffic so as to perform a countermeasure if necessary. Benefitting from the flexible network management offered by SDN and the lightweight Docker container, AsIDPS is able to build a flexible and lightweight defense against DDoS attack in cloud. Based on our prototype implementation, we validate the effectiveness of AsIDPS in defending DDoS attack, and also verify its flexibility and lightweight.
Read moreA study of methodologies used in intrusion detection and prevention systems (IDPS)
Intrusion detection and prevention systems (IDPS) are security systems that are used to detect and prevent security threats to computer systems and computer networks. These systems are configured to detect and respond to security threats automatically there by reducing the risk to monitored computers and networks. Intrusion detection and prevention systems use different methodologies such as signature based, anomaly based, stateful protocol analysis, and a hybrid system that combines some or all of the other systems to detect and respond to security threats. The growth of systems that use a combination of methods creates some confusion when trying to choose a methodology and system to deploy. This paper seeks to offer a clear explanation of each methodology and then offer a way to compare these methodologies.
Read moreNeural Networks for Intrusion Detection
This paper presents Intrusion Detection Systems (IDS), Intrusion Detection and Prevention Systems (IDPS) and their classification emphasizing on the use of neural networks in IDS. Contemporary IDS usually include both signature verification and anomaly detection approaches realized by rule-based expert system and statistical module correspondingly. Neural networks may be used mainly as additional module to the statistical module to better recognize the user behavior. User behavior may be represented as frequency pattern of users command history. The paper presents an example of user profile vector for Unix-based platforms.
Read moreAI-Powered Intrusion Detection and Prevention Systems for the Next Generation Network
The rapid evolution of next-generation networks (NGNs), driven by 5G, IoT, edge computing, and software-defined networking, has introduced new opportunities alongside complex security challenges. Traditional intrusion detection and prevention systems (IDS), built on signature-based and anomaly-based methods, struggle to cope with the scale, heterogeneity, and dynamic threat landscape of NGNs. In response, artificial intelligence (AI) has emerged as a powerful enabler of modern IDPS. This review surveys AI-powered approaches, beginning with classical machine learning methods such as decision trees, support vector machines, and random forests, and then examining deep learning architectures including convolutional neural networks (CNNs), recurrent neural networks (RNNs), long short-term memory networks (LSTMs), and autoencoders. It further analyses hybrid frameworks that integrate ensemble learning, federated learning, and meta-learning, as well as specialised methods tailored for SDN, IoT, edge, and cloud/5G environments. Benchmark datasets, including NSL-KDD, CICIDS2017, UNSW-NB15, Bot-IoT, IoT-23, and TON_IoT, are reviewed, highlighting their contributions and limitations. The paper identifies key challenges, including dataset scarcity, generalisation gaps, computational overhead, adversarial robustness, explainability, and privacy. Future directions emphasise the need for realistic NGN datasets, lightweight yet accurate architectures, privacy-preserving and federated frameworks, and integrated detection and prevention mechanisms. Overall, AI-powered IDPS demonstrate significant potential to secure NGNs, but realising this vision will require advances that balance accuracy, efficiency, interpretability, and resilience.
Read moreArtificial Intelligence for Cyber Security: Performance Analysis of Network Intrusion Detection
Cybersecurity has become major progress in the digital era. Contraction is an important component of the cyber analysts’ management of information technology, as several government organizations and commercial enterprises are moving to dispersed systems. A cyber security analyst is most importantly responsible for protecting the network against damage. Attacks on networks are becoming more complex and sophisticated every day. The number of connected workplaces leads to heavy traffic, more security attack vectors, security breaches and raises more issues than the cyber area can handle by using human intervention while there is not enough sizable automation. Network Intrusion, thus, becomes the biggest concern of this generation. Intrusion Detection and Prevention System (IDPS) has become a vital complement to almost all organizations' security infrastructure. This chapter includes three network monitoring tools concentrating on the immediate impact and output of cyber assaults on the network. This helps to better comprehend the many directions in the area of network monitoring and cybersecurity research. In general, this chapter aims to study the different network monitoring techniques that can be used in support of various servers and network devices to better understands the effect of cyber-attacks on the network and monitor it through tools such as cacti, weather-map and smokeping. It also sheds light on techniques like artificial intelligence, machine learning, neural networks, fuzzy logic, next-generation firewall and how they can be coupled with Intrusion Detection System (IDS) to detect attacks on private networks.KeywordsIDPSNetwork monitoring toolsCyber-attacks monitoringCybersecurityNext generation firewall
Read moreAI-Powered Intrusion Detection and Prevention System (IDPS) for Industrial IoT
The accelerated evolution of Industrial Internet of Things (IIoT) 5.0 brings human-centric automation, hyperconnectivity, and Artificial Intelligence (AI) based real-time data analytics. The growth presents cybersecurity challenges with an increased attack surface and advanced threats. Legacy Intrusion Detection and Prevention System (IDPS) are not scalable and lack the agility to deal with these threats. This chapter discusses AI-based IDPS through machine learning, deep learning, and FL to enable real-time threat detection. This chapter also mentions the importance of Explainable AI, blockchain, and edge AI in improving security. The future directions are quantum computing and light AI models, and this provides a roadmap to secure IIoT 5.0 against future cyber-attacks.
Read moreChapter 5 - Intrusion Prevention and Detection Systems
Chapter 5 - Intrusion Prevention and Detection Systems
Importance of the Considering Bottleneck Intermediate Node During the Intrusion Detection in MANET
Routing protocols are responsible to enable efficient communication in any networking environment. Mobile Ad Hoc Networks are an infrastructure-less, distributed and peer-to-peer networks. Most of the routing protocols designed in this network are based on the consideration that the nodes in the network are supportive and cooperate for multi-hop communication. This consideration is not authentic in the hostile environment. The nodes violate the routing protocol specifications and drop the packets, and known as malicious nodes. However, reputed intermediate nodes also drop the packets whenever they receive the packets more than their handling capabilities, and known as bottleneck intermediate nodes. In order to overcome the situation, various intrusion detection and prevention systems (IDS) are designed. The aim of the IDS is to mitigate the packet dropping nodes from network, but they do not recognize the packet dropping node is either malicious or reputed. The paper aim is to investigate the performance of the existing IDS in the presence of the reputed packet dropping nodes in the network. Performance evaluation is carried out by network simulator, NS-2. The results show that neglecting the reputed packet dropping nodes by IDS algorithms is a serious problem and it negatively impacts on the network performance.KeywordsMANETIntrusion detection systemBottleneck nodeRoutingSimulation
Read moreEnhancing Intrusion Detection System Performance Using a Hybrid of Harris Hawks and Whale Optimization Algorithms
Intrusion Detection and Prevention Systems (IDPSs) play a crucial role in safeguarding online connections against unauthorized access and malicious activities. To enable efficient and effective detection and mitigation, IDPSs must continuously improve their performance due to the constantly developing nature of cyber threats. However, an IDPS is more difficult to use and less reliable when it deals with huge amounts of data. This study aimed to improve the performance of IDPSs by employing optimization algorithms to reduce the data size. Particularly, the Harris Hawks Optimization (HHO) and Whale Optimization Algorithm (WOA) were combined for feature selection. The experimental results showed that the performance of the proposed IDPS was greatly improved by combining the HHO and WOA algorithms. Combining a Random Forest classifier with the suggested HHO/WOA feature selection method achieved very high results in accuracy (99.17%), recall (98.76%), precision (98.76%), and F1-score (98.43%).
Read moreBlockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Read moreHybrid bagging and boosting with SHAP based feature selection for enhanced predictive modeling in intrusion detection systems
The novelty and growing sophistication of cyber threats mean that high accuracy and interpretable machine learning models are needed more than ever before for Intrusion Detection and Prevention Systems. This study aims to solve this challenge by applying Explainable AI techniques, including Shapley Additive explanations feature selection, to improve model performance, robustness, and transparency. The method systematically employs different classifiers and proposes a new hybrid method called Hybrid Bagging-Boosting and Boosting on Residuals. Then, performance is taken in four steps: the multistep evaluation of hybrid ensemble learning methods for binary classification and fine-tuning of performance; feature selection using Shapley Additive explanations values retraining the hybrid model for better performance and reducing overfitting; the generalization of the proposed model for multiclass classification; and the evaluation using standard information metrics such as accuracy, precision, recall, and F1-score. Key results indicate that the proposed methods outperform state-of-the-art algorithms, achieving a peak accuracy of 98.47% and an F1 score of 96.19%. These improvements stem from advanced feature selection and resampling techniques, enhancing model accuracy and balancing precision and recall. Integrating Shapley Additive explanations-based feature selection with hybrid ensemble methods significantly boosts the predictive and explanatory power of Intrusion Detection and Prevention Systems, addressing common pitfalls in traditional cybersecurity models. This study paves the way for further research on statistical innovations to enhance Intrusion Detection and Prevention Systems performance.
Read moreDeveloping an Intelligent Intrusion Detection and Prevention System against Web Application Malware
Malware authors are continuously developing crime toolkits. This has led to the situation of zero-day attacks, where malware harm computer systems despite the protection from existing Intrusion Detection Systems (IDSs). We propose an Intelligent Intrusion Detection and Prevention System (IIDPS) approach that combines the Signature based Intrusion Detection system (SIDS), Anomaly based Intrusion Detection System (AIDS) and Response Intrusion Detection System (RIDS). We used a risk assessment approach to determine an appropriate response action against each attack event. We also demonstrated the IIDPS make the detection and prevention of malware more effective.
Read moreHyperion: A Visual Analytics Tool for an Intrusion Detection and Prevention System
Intrusion detection and prevention systems (IDPSs) are at the core of protecting an enterprise's network. In general, IDPSs use pre-defined rules to detect potential attacks. As the size of an organization grows and new types of intrusions appear, the quantity and complexity of the rules also increase. Moreover, IDPSs generate an overwhelming number of logs that are challenging to handle and analyze. For a more effective and integrative analysis and management of the rules and logs, we propose a novel visual analytics tool, Hyperion. Hyperion interactively visualizes rules to help users understand how the IDPS rules are managed and applied to the enterprise's network entities. Hyperion also provides effective visualizations to enable users to visually analyze the type, period, traffic, and frequency of attacks in addition to a traditional count-based timeline visualization. Finally, Hyperion enables users to interactively simulate the effect of a change in parameters of a detection rule. These features can help streamline the security control cycle consisting of rule application, information collection, log analysis, and rule revision.
Read more