
A prototype implementation of a network-level intrusion detection system. Technical report number CS91-11
Author(s) -
R. Heady,
George F. Luger,
A.B. Maccabe,
Mark Servilla,
Jessica L. Sturtevant
Publication year - 1991
Language(s) - English
Resource type - Reports
DOI - 10.2172/425286
Subject(s) - intrusion detection system , network packet , computer science , protocol (science) , packet analyzer , computer network , host based intrusion detection system , real time computing , network monitoring , intrusion prevention system , data mining , medicine , alternative medicine , pathology
This paper presents the implementation of a prototype network level intrusion detection system. The prototype system monitors base level information in network packets (source, destination, packet size, time, and network protocol), learning the normal patterns and announcing anomalies as they occur. The goal of this research is to determine the applicability of current intrusion detection technology to the detection of network level intrusions. In particular, the authors are investigating the possibility of using this technology to detect and react to worm programs