Intrusion Detection by Intelligent analysis of data across multiple gateways in real-time.
Scanlan, J and Lorimer, S and Hartnett, J and Manderson, K (2004) Intrusion Detection by Intelligent analysis of data across multiple gateways in real-time. Working Paper. UNSPECIFIED.
|PDF - Requires a PDF viewer|
Current firewalls and intrusion detection systems are generally designed to protect a single gateway in order to provide protection for machines residing behind the gateway on an internal network. When considering a network incorporating multiple gateways across a range of IP addresses exposed to the Internet, interesting data can be gathered with regard to the types of scans occurring across these gateways from the outside. The validity of using a central server to amalgamate, reduce and analyse the log files of each gateway is investigated in order to examine the activities of the scans across multiple gateways and port numbers. The results from this analysis can then be used to act against an attack through
heuristic driven rule creation.
|Item Type:||Report (Working Paper)|
|Keywords:||Intrusion Detection, Firewall, Multiple Gateway, Analysis|
|Deposited By:||utas eprints|
|Deposited On:||17 Aug 2004|
|Last Modified:||18 Jul 2008 19:37|
|ePrint Statistics:||View statistics for this ePrint|
Available Versions of this Item
- Intrusion Detection by Intelligent analysis of data across multiple gateways in real-time. (deposited 17 Aug 2004) [Currently Displayed]
Repository Staff Only: item control page