2008Unpublished venueRequires access

NetFlow Based Intrusion Detection System

Wang Zhenqi, Wang Xinyu

Open publisher page 28 citations

Abstract

As a opening global network, Internet now is facing more and more attacks and complex methods of attack, which causes the network security problem becoming the focal point that people pay attention to.The single firewall strategy can not satisfy the need of network security, intrusion detection system which is used at present has very high rate of false alarm. However, intrusion detection system based on NetFlow can solve these problems. NetFlow provides IP flow information in the network. Network administrators can use the NetFlow flow records for a variety of purposes, including network management, network planning, network security and so on. In the field of network security, IP flow information provided by NetFlow is used to analyze anomaly traffic. NetFlow based anomaly traffic analysis is an appropriate supplement to current signature-based NIDS. In this paper, we propose a NetFlow based intrusion detection system, which can detect several types of network attack from inside or outside based on the NetFlow data exported from the router or other network probes. And this system can take the ensures to prevent these types of network attack.

About this research paper

What this paper is about

As a opening global network, Internet now is facing more and more attacks and complex methods of attack, which causes the network security problem becoming the focal point that people pay attention to.The single firewall strategy can not satisfy the need of network security, intrusion detection system which is used at present has very high rate of false alarm. However, intrusion detection system based on NetFlow can solve these problems. NetFlow provides IP flow information in the network. Network administrators can use the NetFlow flow records for a variety of purposes, including network management, network planning, network security and so on. In the field of network security, IP flow information provided by NetFlow is used to analyze anomaly traffic. NetFlow based anomaly traffic analysis is an appropriate supplement to current signature-based NIDS. In this paper, we propose a NetFlow based intrusion detection system, which can detect several types of network attack from inside or outside based on the NetFlow data exported from the router or other network probes. And this system can take the ensures to prevent these types of network attack.

Why it matters

OpenAlex reports 28 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

As a opening global network, Internet now is facing more and more attacks and complex methods of attack, which causes the network security problem becoming the focal point that people pay attention to.The single firewall strategy can not satisfy the need of network security, intrusion detection system which is used at present has very high rate of false alarm. However, intrusion detection system based on NetFlow can solve these problems. NetFlow provides IP flow information in the network. Network administrators can use the NetFlow flow records for a variety of purposes, including network management, network planning, network security and so on. In the field of network security, IP flow information provided by NetFlow is used to analyze anomaly traffic. NetFlow based anomaly traffic analysis is an appropriate supplement to current signature-based NIDS. In this paper, we propose a NetFlow based intrusion detection system, which can detect several types of network attack from inside or outside based on the NetFlow data exported from the router or other network probes. And this system can take the ensures to prevent these types of network attack.

Key concepts: NetFlow, Computer science, Network security, Intrusion detection system, Computer network, Router, Anomaly detection, Computer security

Related papers

Back to paper searchBrowse research topicsOriginal source
NetFlow Based Intrusion Detection System — Research Paper | ScholarLens