This paper presents an enhanced version of Wireshark which, as a lightweight IDS, incorporates various advanced filtering techniques, an ML-based traffic classification, and real-time alerting capabilities. Still based on traditional signature-based filters, the system tags specific attack patterns; a traffic classifier based on Random Forest classifies network traffic as benign or attendant to malicious activity. Because of Lua scripting, the real-time alert capability has been integrated to respond to an on-time threat. The upgrades have been evaluated against KDD Cup 1999 dataset in a simulated cloud environment, within which a high-performance accuracy rate of 98.2 was achieved. Results establish the feasibility of Wireshark as a scalable and effective IDS, suitable both for classical and cloud-based networks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing Wireshark with Advanced Filtering and Traffic Classification for IDS Applications

  • Bharath Reddy Chukka,
  • S. Aruna Deepthi,
  • E. Sreenivasa Rao

摘要

This paper presents an enhanced version of Wireshark which, as a lightweight IDS, incorporates various advanced filtering techniques, an ML-based traffic classification, and real-time alerting capabilities. Still based on traditional signature-based filters, the system tags specific attack patterns; a traffic classifier based on Random Forest classifies network traffic as benign or attendant to malicious activity. Because of Lua scripting, the real-time alert capability has been integrated to respond to an on-time threat. The upgrades have been evaluated against KDD Cup 1999 dataset in a simulated cloud environment, within which a high-performance accuracy rate of 98.2 was achieved. Results establish the feasibility of Wireshark as a scalable and effective IDS, suitable both for classical and cloud-based networks.