A fast and accurate threat detection and prevention architecture using stream processing - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue (Data Paper) Concurrency and Computation: Practice and Experience Année : 2022

A fast and accurate threat detection and prevention architecture using stream processing

Antonio Lobato
Martin Andreoni Lopez
Alvaro Cardenas
Otto Carlos M. B. Duarte
Guy Pujolle

Résumé

ate detection of security breaches increases the risk of irreparable damages and limits any mitigation attempts. We propose a fast and accurate threat detection and prevention architecture that combines the advantages of real-time streaming with batch processing over a historical database. We create a dataset by capturing both legitimate and malicious traffic and propose two ways of combining packets into flows, one considering a time window and the other analyzing the first few packets of each flow per period. We also investigate the effectiveness of our proposal on real-world network traces obtained from a significant Brazilian network operator providing broadband Internet to their customers. We implement and evaluate three classification algorithms and two anomaly detection methods. The results show an accuracy higher than 95% and an excellent trade-off between attack detection and false-positive rates. We further propose an improved scheme based on software defined networks that automatically prevents threats by analyzing only the first few packets of a flow. The proposal promptly and efficiently blocks threats, is robust, and can scale up, even when the attacker employs spoofed IP.
Fichier non déposé

Dates et versions

hal-03920611 , version 1 (03-01-2023)

Identifiants

Citer

Antonio Lobato, Martin Andreoni Lopez, Alvaro Cardenas, Otto Carlos M. B. Duarte, Guy Pujolle. A fast and accurate threat detection and prevention architecture using stream processing. Concurrency and Computation: Practice and Experience, 2022, 34 (3), pp.e6561. ⟨10.1002/cpe.6561⟩. ⟨hal-03920611⟩
8 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More