الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

بعض المقاييس لإكتشاف الintrusions

مغلق
بدأه النغم الخجول في 14 أبريل 2007 · 7 رد · 1,873 مشاهدة · في برمجة الشبكات والتطبيقات الموزعة
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم

أنا في صدد عمل برنامج لكشف التطفل على الشبكة ولكن الجزء الرئيسي الذي ينقصني هو

تحديد المعايير التي على أساسها أستطيع أن أقول إذا كان الـpacket intrusive أو لا

فهل لديكم مقاييس مفيدة يعني مثلا وقت بقاء الباكت أو أي شيء آخر

والمقياس الذي تقترحوه لحل أي نوع من الــAttacks يعني هل يكتشف DoS or Spoofing...etc

أرجو من أهل الخبرة الإهتمام للضرورة

شكرا للجميع

النغم الخجول

14_07_06_10_56_13_1152942973_6__4__6__1_5__56_1144313576165_8_-6.jpg

#2

في العادة يمكن اكتشاف DoS Attack بعدد الـPackets المرسلة من مصدر ما خلال فترة زمنية معينة وكمثال في حالة كان المصدر A يرسل The Same Contents in All Packets للهدف B عندها يمكن قياس الـTimespan بين كل Packet واخر فإذا كانت متكررة وبفترات متقاربة عندها يمكن عمل اجراء معين لحجب الـPackets المرسلة من A كوضع Access Role باستخدام الـSocket Permission ...

لكن اكتشاف الـ Intrusive Packet ليس بهذه البساطة إذ يمكن مثلا تغيير اما محتويات الـPacket أو حجمه او اي شيء اخر مما يعيق عملية تمييز الـ intrusive Packetعن غيره وهنا يمكن ارجاع الموضوع إلى اجراءات الذكاء الأصطناعي لتمييز تلك Packets ...

#3

السلام عليكم

مشكور أخي فادي جزاك الله خيرا.

انا ايضا مهتم بهذا الموضوع Implementing AI techniques in security problems

و الملف المرفق به نبذه عن Neural network based Intrusion Detection System

أتمني ان يفيدك.

There is also a project called "Snort" which is an open source Intrusion Detection System

You can benefit alot from it.

snort

;-)

Neural_network_based_intrusion_detection.pdf

يا نفس كفي عن العصيان واكتسبي ----- فعلا جميلا لعل الله يرحمني

#4

السلام عليكم

These are some informations ....

What do I need in IDS?

Intrusion detection describes the intention - not the methodology. There are several different ways by which this can be achieved; so anything that detects intrusions is an IDS. Which method you choose really depends upon what you need: and if you don't already have in-house security expertise, it would be worth employing a consultant to help reach your decision.

Note that IDS is no longer a new technology - it's a mature technology. Since the term is no longer new, it no longer has that 'buzz' required by marketing managers. This has been aggravated by analyst firm the Gartner Group proclaiming that IDS is dead and replaced by IPS. This is wrong. Ignore it. IPS is different to IDS. Vend ors and security experts know this, but the result is that manufacturers are tempted to find new terms - and one of these is Network Behavior Analysis. This is a good and useful approach; but one of the primary purposes of NBA is to detect intrusions – in other words, IDS.

Remember, too, that good security is the right level of security for you. You need to strike the right balance between the cost of the security and the value of your goods - there's no point in spending more on security than the value of what you're protecting. Risk management principles using a thorough risk analysis will help you decide how much to spend.

Armed with this information, you can look for features such as:

• attack halting (stops the attack, whether it is a program or a hacker)

• attack blocking (closes the loop-hole through which the attacker gained access)

• attack alerting (either pop-up to an online admin, or email or SMS to a remote admin)

• information collecting (on what is done by the attack to the network, and from where the attack came - helps gather forensic evidence should a prosecution become necessary or possible)

• full reporting (so that you can learn from your mistakes, and prevent future problems)

• fail-safe features (such as encrypted messages and VPN tunneling within the IDS to hide its presence from, and inhibit interference by, any hacker).

If you've got a large network, or particularly valuable information, you may like to look out for the extras offered with some intrusion detection systems:

• honeypot or padded cell (a fake network or area designed specifically to attract and contain attacks, so that you can analyze them and learn from their behavior)

• vulnerability analysis (so that you can check your network for all known vulnerabilities in order to pre-empt rather than just detect intrusions)

• file integrity checker (a mathematical way of knowing if a file has been altered in any way, and therefore potentially compromised by an intruder)

One other point - don't think that you're so small you don't need or can't find an IDS. IDS as described above is available for large enterprises on down. But even if you just have a couple of PCs, you can still get, and still need, an intrusion detection system. It's just that for a single desktop system it goes by different names and has less automated features: it's a personal firewall and an anti-spyware program. The purpose is the same - to detect and stop intrusions - it's just that here you have to manually keep it up to date and manually conduct regular scans and it isn’t as intelligent or sophisticated.

------------------------------------------------------------------

And the following is the Characteristics of a Good IDS

Run continually without supervision.

Be fault-tolerant.

Do not use excessive system resources.

Able to observe deviation from normal behavior.

Able to cope with changing system behavior over time. As new applications are added, the system profile will change automatically, and the IDS must be able to adapt.

Be accurate (0% false positive and 0% false negative).

Be customizable.

Be current (i.e. signature files and baseline data are up-to-date)

#5

شكرا لكم جميعا على هذا الاهتمام

النغم الخجول

14_07_06_10_56_13_1152942973_6__4__6__1_5__56_1144313576165_8_-6.jpg

#6
فادي عبدالقادر كتب:
في العادة يمكن اكتشاف DoS Attack بعدد الـPackets المرسلة من مصدر ما خلال فترة زمنية معينة وكمثال في حالة كان المصدر A يرسل The Same Contents in All Packets للهدف B عندها يمكن قياس الـTimespan بين كل Packet واخر فإذا كانت متكررة وبفترات متقاربة عندها يمكن عمل اجراء معين لحجب الـPackets المرسلة من A كوضع Access Role باستخدام الـSocket Permission ...

لكن اكتشاف الـ Intrusive Packet ليس بهذه البساطة إذ يمكن مثلا تغيير اما محتويات الـPacket أو حجمه او اي شيء اخر مما يعيق عملية تمييز الـ intrusive Packetعن غيره وهنا يمكن ارجاع الموضوع إلى اجراءات الذكاء الأصطناعي لتمييز تلك Packets ...

السلام عليكم

اخ فادي احاول ان اطبق مثل هذه العملية في مشروع التخرج هل هناك simulation معين استطيع من خلاله ان اقوم بهذه العملية حيث انه من الصعب توفر عدد من الاجهزة لتنفيذ network

واذا صعب الامر ساحاول ان اربط حاسبتين واقوم بهذه العملية

او اذا كان هناك برنامج تم عمله او سورس كود ارجو المساعدة وشكرا

#7
النغم الخجول كتب:
السلام عليكم

أنا في صدد عمل برنامج لكشف التطفل على الشبكة ولكن الجزء الرئيسي الذي ينقصني هو

تحديد المعايير التي على أساسها أستطيع أن أقول إذا كان الـpacket intrusive أو لا

فهل لديكم مقاييس مفيدة يعني مثلا وقت بقاء الباكت أو أي شيء آخر

والمقياس الذي تقترحوه لحل أي نوع من الــAttacks يعني هل يكتشف DoS or Spoofing...etc

أرجو من أهل الخبرة الإهتمام للضرورة

شكرا للجميع

حصلت على document من شركىة سيسكو يشرح فيها المعايير التي تحدد ان كانت ال ـpacket intrusive

ان ايضا احتاج الى معاونة في هذا المشروع اذا عوانتني سوف ارسلها لك

#8

مرحبا iraqi_it_84

أنا أكملت هذا المشروع العام الماضي ولكن الآن عندما أقيمه أجد مستواه غير جيد مقارنة بأقرانه ولكن بالنسبة لمواردي وقله أو بالأصح انعدام مساعديني أجده ممتاز جدا!!

لقد قيل لي أن عدد مرات الإرسال من نفس الجهاز إلى جهاز معين ليست مقياس منطقي لأن الرسالة قد تكون طويلة وبالتالي فإن عدد الباكتس سيكون كبير!!

بالتوفيق

النغم الخجول

14_07_06_10_56_13_1152942973_6__4__6__1_5__56_1144313576165_8_-6.jpg

هذا الموضوع مغلق.

مواضيع مشابهة