Login

Login
Welcome:
Guest

Search for:


Browse:

Bannner: Aslib individual membership.
 
Journal search
Journal cover: Information Management & Computer Security

Information Management & Computer Security

ISSN: 0968-5227

Online from: 1993

Subject Area: Information and Knowledge Management

Content: Latest Issue | icon: RSS Latest Issue RSS | Previous Issues

Options: To add Favourites and Table of Contents Alerts please take a Emerald profile

Previous article.Icon: Print.Table of Contents.Icon: .

Design of a multimedia traffic classifier for Snort


Document Information:
Title:Design of a multimedia traffic classifier for Snort
Author(s):Oge Marques, (Florida Atlantic University, Boca Raton, Florida, USA), Pierre Baillargeon, (Scripps Research Institute, Jupiter, Florida, USA)
Citation:Oge Marques, Pierre Baillargeon, (2007) "Design of a multimedia traffic classifier for Snort", Information Management & Computer Security, Vol. 15 Iss: 3, pp.241 - 256
Keywords:Computer networks, Data security, Signal detection
Article type:Research paper
DOI:10.1108/09685220710759577 (Permanent URL)
Publisher:Emerald Group Publishing Limited
Abstract:

Purpose – The purpose is to enhance the capabilities of a general-purpose IDS solution with additional knowledge of multimedia file formats and protocols, to better handle multimedia-specific security exploits.

Design/methodology/approach – The authors have designed a multimedia traffic classifier, implemented as an optional preprocessor for Snort. The solution has been successfully tested with downloading and streaming traffic.

Findings – Test results confirm that the additional specialized knowledge encoded in the preprocessor results in two significant gains: trusted multimedia contents can be identified and allowed to bypass the detection engine, with substantial computational savings; the IDS is now able to detect multimedia-specific exploits which would otherwise go unnoticed.

Research limitations/implications – Not all multimedia-related scenarios have been covered by the described implementation yet. The proposed solution is being extended to other file types and protocols, fine-tuned, as well as tested more extensively.

Practical implications – Snort users interested in this work will be able to add the multimedia-specific functionality – and enjoy the resulting benefits – with minimal effort.

Originality/value – The research reported in this paper is – to the authors' knowledge – the first effort to add multimedia-specific knowledge to the operation of an IDS. In addition to being innovative, the proposed method is relevant for more than one reason, since it enhances the IDS capabilities while at the same time alleviating the computational cost of performing detailed traffic analysis in high-speed networks.



Fulltext Options:

Login

Login

Existing customers: login
to access this document

Login


- Forgot password?

- Athens/Institutional login

Purchase

Purchase

Downloadable; Printable; Owned
HTML, PDF (482kb)Purchase

To purchase this item please login or register.

Login


- Forgot password?

Recommend to your librarian

Complete and print this form to request this document from your librarian


Marked list

Bookmark & share

Reprints & permissions

© Emerald Group Publishing Limited  |  Copyright information  |  Site policies  |  Cookie information
..