University of Tasmania
Browse

File(s) under permanent embargo

A context aware attack detection system

journal contribution
posted on 2023-05-25, 22:40 authored by Joel ScanlanJoel Scanlan, Hartnett, J
It is well known that intrusion detection systems can make smarter decisions if the context of the traffic being observed is known. This paper examines whether an attack detection system, looking at traffic as it arrives at gateways or firewalls, can make smarter decisions if the context of attack patterns across a class of IP addresses is known. A system that detects and forestalls the continuation of both fast attacks and slow attacks across several IP addresses is described and the development of heuristics both to ban activity from hostile IP addresses and then lift these bans is illustrated. The system not only facilitates detection of methodical multiple gateway attacks, but also acts to defeat the attack before penetration can occur.

History

Publication title

IJCSNS International Journal of Computer Science and Network Security

Volume

8

Article number

1

Number

1

Pagination

75-84

ISSN

1738-7906

Publication status

  • Published

Repository Status

  • Restricted

Usage metrics

    University Of Tasmania

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC