Research on network security and intrusion detection strategies presents many challenging issues to both theoreticians and practitioners. Hackers apply an array of intrusion and exploit techniques to cause disruption of normal system operations, but on the defense, firewalls and intrusion detection systems (IDS) are typically only effective in defending known intrusion types using their signatures, and are far less than mature when faced with novel attacks. In this paper, we adapt the frequency analysis techniques such as the Discrete Fourier Transform (DFT) used in signal processing to the design of intrusion detection algorithms. We demonstrate the effectiveness of the frequency-based detection strategy by running synthetic network intrusion data in simulated networks using the OPNET software. The simulation results indicate that the proposed intrusion detection strategy is effective in detecting anomalous traffic data that exhibit patterns over time, which include several types of DOS and probe attacks. The significance of this new strategy is that it does not depend on the prior knowledge of attack signatures, thus it has the potential to be a useful supplement to existing signature-based IDS and firewalls.
[1]
Zheng Zhang,et al.
HIDE : a Hierarchical Network Intrusion Detection System Using Statistical Preprocessing and Neural Network Classification
,
2001
.
[2]
Shabana Razak.
Network intrusion simulation using OPNET
,
2002
.
[3]
Tao Wan,et al.
IntruDetector: a software platform for testing network intrusion detection algorithms
,
2001,
Seventeenth Annual Computer Security Applications Conference.
[4]
Kyoji Kawagoe,et al.
A similarity search method of time series data with combination of Fourier and wavelet transforms
,
2002,
Proceedings Ninth International Symposium on Temporal Representation and Reasoning.
[5]
Kristopher Kendall,et al.
A Database of Computer Attacks for the Evaluation of Intrusion Detection Systems
,
1999
.
[6]
Li Jun,et al.
HIDE: a Hierarchical Network Intrusion Detection System Using Statistical Preprocessing and Neural Network Classification
,
2001
.
[7]
Divyakant Agrawal,et al.
A comparison of DFT and DWT based similarity search in time-series databases
,
2000,
CIKM '00.