Model of Intrusion Prevention System Based on Dynamic IP Blacklist

LU Xian-feng,YANG Pin,LIANG Gang
DOI: https://doi.org/10.16208/j.issn1000-7024.2011.01.073
2011-01-01
Abstract:NIPS(network intrusion prevention systems) often has a high loss rate and low-performance when handling the huge attack traffic.A model of NIPS based on dynamic IP blacklist is proposed to solve this problems.NIPS maintain a hash table(IP blacklist) while keep the attacker's IP address and their threat values.Through the attacker's IP's threat evaluation algorithm,NIPSwill periodically compute the attacker's threat values and save them into the hash table.While huge network flow reaches,NIPS can rapidly filter the flow beforehand bymeans of using the IP blacklist hash table.The experiments showed that using this model can improve the performance of NIPS and make the protected network safer.
What problem does this paper attempt to address?