Download Intelligent Intrusion Detection System - Nitin Bhatia

Transcript
56
Ed
Lk
(|1G
ZE
Dow QD. Iodr
A
Il
\
I
0he
I0o
,
Qy5.[ O
htrtp:1oxmr m.
GtA~ppile_%
ME L Ad EN
SOS
B
0tr
.ed61
ass
Pax-
WCP~OTMS.c.M - T. .. SsoI
CoT.N
f ows *
TA
.
dSo: Negato,...
9j ,, .
C.
tat,
I
SNORTER
Rapof
_
lcolhool
fl.r th. SNORTNowk Lebiane Dat.-ti
ti.eA -uti
onort
Syn.
so
3-_1e~ss2-U2005-02-1520-0-510
,
or
,....n0
-
;
:
.-
I
:
~~~~~~~~~~M
-
W
d-
- - -h
Figure 4.2 Login andActivity Graph ofAttackers IP Addresses
Figure 4.3 shows the detailed dispersion graph of attackers IP addresses. Dispersion
graph information is obtained by calculating the standard deviation from the different
type of attacks generated by a particular attacker after obtaining the stored information in
the MySQL database. Standard Deviation (SD) is calculated based on various attacks
done of various levels, such as high, medium and low by a particular attack IP address.
The SD calculation starts from the time since IIDS system came online and Snort started
sniffing packets on network, which were stored in MySQL database. Statistical approach
is used here to identify an attacker doing different attacks at various times, thinking
attackers activities will not be noticed by a dedicated IDS system like Snort or firewalls