Sampling method for network intrusion detection

JIN Qing-hui,WANG Dong,YANG Jian-hua,XIE Gao-gang
DOI: https://doi.org/10.3969/j.issn.1001-3695.2008.10.062
2008-01-01
Abstract:Packet sampling which was widely used in network monitoring is a good method to upgrade data packet processing capacity.But the traditional packet sampling algorithm will result in substantial intrusion detection rate reduction.This paper raised a new packet sampling algorithm which used the normal and attacks flow of traffic in the continuity of time against intrusion detection.It could improve IDS's packet processing capacity in the premise,there was still very good detection rate.
What problem does this paper attempt to address?