A Lone Wolf No More: Supporting Network Intrusion Detection with Real-Time Intelligence

For network intrusion detection systems it is becoming increasinglydifficult to reliably report today’s complex attacks withouthaving external context at hand. Unfortunately, however, today’s IDScannot readily integrate intelligence, such as dynamic blacklists, into theiroperation. In this work, we introduce a fundamentally new capabilityinto IDS processing that vastly broadens a system’s view beyond what isvisible directly on the wire. We present a novel Input Framework thatintegrates external information in real-time into the IDS decision process,independent of specific types of data, sources, and desired analyses. Weimplement our design on top of an open-source IDS, and we report initialexperiences from real-world deployment in a large-scale network environment.To ensure that our system meets operational constraints, wefurther evaluate its technical characteristics in terms of the intelligencevolume it can handle under realistic workloads, and the latency withwhich real-time updates become available to the IDS analysis engine. Theimplementation is freely available as open-source software.


Proceedings of the 15th International Symposium on Attacks, Intrusions, and Detections (RAID 2012), pp. 314-333, Amsterdam, the Netherlands

